SonicWall SMA1000 Zero-Day Vulnerabilities Under Active Exploitation

SonicWall SMA1000 Zero-Day Vulnerabilities Under Active Exploitation

First seen 2 Sep 2026, 15:44 UTC News.SophosNcsa.QaGround.Newswww.heise.deSecurityaffairs.Co+2 80.8

Article Content

Browse articles
ThreatCluster

SonicWall has patched two critical zero-day vulnerabilities in its SMA1000 VPN appliances, CVE-2026-83548 and CVE-2026-83549, which are actively being exploited in the wild. CVE-2026-83548 is a pre-authentication SSRF flaw with a CVSS score of 10.0, allowing unauthenticated attackers to access sensitive functionality. CVE-2026-83549 is a post-authentication command injection vulnerability with a CVSS score of 7.8, enabling authenticated attackers to execute arbitrary commands. SonicWall confirmed that attackers are likely chaining these vulnerabilities to achieve remote code execution. The affected models include SMA 1000 series appliances running specific versions of firmware. SonicWall has urged customers to apply the latest hotfix immediately and check for signs of compromise. This incident marks the second significant security issue affecting the SMA product line within a month. The vulnerabilities were disclosed on September 1, 2026, and are part of ongoing security concerns for SonicWall products.

Key Points: • Two critical zero-day vulnerabilities in SonicWall SMA1000 appliances are actively exploited. • CVE-2026-83548 (CVSS 10.0) allows unauthenticated access, while CVE-2026-83549 (CVSS 7.8) enables command injection. • SonicWall recommends immediate patching and system checks for signs of compromise.

Timeline

2026-07-14
CVE-2026-15409 and CVE-2026-15410 published
SonicWall disclosed two vulnerabilities in SMA 1000 appliances, later confirmed to be exploited.
Securityaffairs.Co
2026-09-01
CVE-2026-83548 and CVE-2026-83549 published
SonicWall disclosed two new zero-day vulnerabilities in SMA 1000 appliances, confirming active exploitation.
Ground.News
2026-09-02
SonicWall urges immediate patching
SonicWall advised customers to apply hotfixes for the vulnerabilities and check for compromises.
Ncsa.Qa