SonicWall Warns of Actively Exploited SMA1000 Zero-Day Flaws
SonicWall said hotfixes are available as attackers use a 10.0-rated flaw and a command injection bug to reach corporate networks.
- SonicWall is urging customers to apply hotfixes after identifying two actively exploited zero-day vulnerabilities in SMA1000 series appliances that could allow attackers to compromise enterprise networks.
- The first, CVE-2026-83548, is a pre-authentication SSRF vulnerability with a maximum CVSS score of 10.0; the second, CVE-2026-83549, is a post-authentication OS command injection issue in the Appliance Management Console rated 7.8.
- NHS England warned that internet-facing gateways face growing attack risks, stating "firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers," with future exploitation assessed as almost certain.
- SonicWall released hotfixes for affected appliances, and if systems appear compromised, the vendor recommends reimaging, changing all passwords, and resetting TOTP tokens to secure the network.
- These disclosures continue a difficult trend for SonicWall's SMA1000 line, which saw a succession of vulnerabilities throughout 2025, including a similar pair of SSRF and OS command injection flaws in July of last year.
21 Articles
21 Articles
SonicWall reports two major security holes under active exploit
SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authentication, highly troubling. In its security alert, SonicWall described the first hole, tracked as CVE-2026-83548 and rated 10 (critical) in severity, as a “Pre-authentication …
SonicWall urges immediate patching of chained vulnerabilities | #ransomware | #cybercrime - National Cyber Security Consulting
Security researchers warn that hackers are chaining a maximum-severity vulnerability in the SonicWall SMA1000 appliances with a high-severity flaw to achieve remote code execution. A critical server-side request forgery flaw in the Appliance Work Place interface, tracked as CVE-2026-83548, allows an attacker to access sensitive functions and perform unauthorized actions. The vulnerability has a severity […] Thank you for subscribing to our RSS …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium














