Securityaffairs.Co
SonicWall SMA1000 Faces Third Zero-Day Exploitation in 2026
Article Content
SonicWall's SMA1000 VPN appliances are under active exploitation due to two newly discovered zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which were confirmed on September 1, 2026. The first vulnerability, an SSRF flaw with a CVSS score of 10.0, allows unauthenticated attackers to gain unauthorized access to sensitive functionalities. The second vulnerability, an OS command injection flaw with a CVSS score of 7.8, requires administrator-level access but can lead to arbitrary command execution. Attackers are chaining these vulnerabilities to achieve full compromise of affected systems, which include models 6210, 7210, and 8200v. SonicWall has released patches for these vulnerabilities, urging affected organizations to upgrade immediately. The ongoing exploitation has raised significant concerns among enterprise and government organizations relying on these VPN appliances. Previous incidents involving the same product line indicate a troubling trend of repeated vulnerabilities and exploitation.
Key Points: • SonicWall SMA1000 appliances face active exploitation of two critical vulnerabilities. • CVE-2026-83548 (CVSS 10.0) allows unauthenticated access, while CVE-2026-83549 (CVSS 7.8) requires admin access. • SonicWall has issued patches and urges immediate action from affected organizations.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.