Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

SonicWall vulnerability

SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild. 

According to an advisory published by SonicWall on Tuesday, the vulnerabilities and their exploitation were discovered internally. 

One of the flaws, tracked as CVE-2026-83548 with a CVSS score of 10, has been described as a pre-authentication SSRF issue in the Appliance Work Place interface of SMA1000 appliances. An attacker can exploit it remotely without authentication to access sensitive functionality and conduct unauthorized operations.

The second vulnerability, tracked as CVE-2026-83549 with a CVSS score of 7.8, is an OS command injection issue in the Appliance Management Console (AMC) component.

An authenticated attacker can exploit it to execute arbitrary OS commands, potentially resulting in remote code execution. 

SonicWall noted in its advisory that it has observed exploitation of both vulnerabilities, which suggests they have been chained in attacks. 

Advertisement. Scroll to continue reading.

SMA1000 models 6210, 7210, and 8200v are affected by the zero-days. Hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions patch the vulnerabilities. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected.

No details appear to be available on the attacks exploiting CVE-2026-83548 and CVE-2026-83549, and the vendor’s public advisory does not include indicators of compromise (IoCs).

SonicWall product vulnerabilities are regularly exploited in the wild, including in ransomware attacks. Some security holes are exploited for weeks before they are patched. 

CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 17 SonicWall product flaws; CVE-2026-83548 and CVE-2026-83549 have not yet been added.

Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

Related: Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

Related: SonicWall Urges Immediate Patching of Firewall Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Sectigo has named Ian Hassard as Chief Product Officer.

Australian Securities Exchange has appointed Hanlie Botha as Deputy Chief Information Security Officer.

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.