Securityaffairs.Co
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
Article Content
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access sensitive functionality. CVE-2026-83549 is a post-authentication OS command injection flaw rated 7.8, enabling attackers with admin access to execute arbitrary commands. Both vulnerabilities can be chained for unauthenticated remote code execution (RCE). Affected models include the SMA1000 series 6210, 7210, and 8200v, with SonicWall urging immediate patching to versions 12.4.3-03526 or 12.5.0-02952. The vulnerabilities were confirmed as being exploited in the wild as of September 1, 2026. Organizations are advised to review their systems for signs of compromise and reset credentials if any indicators are found.
Key Points: • Two critical vulnerabilities in SonicWall SMA1000 appliances are actively exploited. • CVE-2026-83548 allows unauthenticated access, while CVE-2026-83549 enables command execution. • Immediate patching is required to mitigate risks associated with these vulnerabilities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.