news.mlab.sh
Back to the feed
vulnerability

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

HighCVSS 7.8
Summary

SonicWall has warned customers of its SMA1000 series appliances about two actively exploited zero-day vulnerabilities. These flaws allow attackers to bypass authentication and execute commands on the device, posing a significant risk of remote code execution. SonicWall urges immediate patching to mitigate the threat.

SonicWall is alerting customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance platform to address two critical zero-day vulnerabilities that are currently being exploited in the wild. The vulnerabilities have been discovered internally by SonicWall’s security team.

One of the flaws, identified as CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) issue within the Appliance Work Place interface. An attacker can leverage this vulnerability to access sensitive functionality and carry out unauthorized operations without needing to authenticate.

The second vulnerability, CVE-2026-83549, is an OS command injection issue located in the Appliance Management Console (AMC) component. An authenticated attacker can exploit this to execute arbitrary operating system commands, potentially leading to remote code execution.

SonicWall’s advisory indicates that both vulnerabilities are being actively exploited, suggesting they are being chained together in attacks. Affected models include SMA1000 models 6210, 7210, and 8200v. Hotfixes 12.4.3-03526, 12.5.0-02952, and later versions are available to address these issues.

SSL-VPN running on SonicWall firewalls or SMA100 series products is not impacted by these vulnerabilities. The CISA’s Known Exploited Vulnerabilities (KEV) catalog has not yet added CVE-2026-83548 and CVE-2026-83549. SonicWall products are frequently targeted and exploited, sometimes for weeks before patches are released.

Read the full article at SecurityWeek