[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6gsUfC0jsN-ebL5TPC7blMcfSX3vcvFDhuqKL2MgF9E":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"5ebd8333-9751-435b-806f-ba3c6c402783","SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks","sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks-3e24cc","The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.","SonicWall has issued an urgent warning to customers regarding two zero-day vulnerabilities in its SMA1000 series secure remote access gateway and SSL-VPN appliance. The flaws, CVE-2026-83548 and CVE-2026-83549, have been observed being exploited in the wild, potentially chained together for unauthenticated remote code execution. Affected models include 6210, 7210, and 8200v, with hotfixes available for patching.","SonicWall warns of two zero-day vulnerabilities in SMA1000 devices being exploited.","SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild. According to an advisory published by SonicWall on Tuesday, the vulnerabilities and their exploitation were discovered internally. One of the flaws, tracked as CVE-2026-83548 with a CVSS score of 10, has been described as a pre-authentication SSRF issue in the Appliance Work Place interface of SMA1000 appliances. An attacker can exploit it remotely without authentication to access sensitive functionality and conduct unauthorized operations. The second vulnerability, tracked as CVE-2026-83549 with a CVSS score of 7.8, is an OS command injection issue in the Appliance Management Console (AMC) component. An authenticated attacker can exploit it to execute arbitrary OS commands, potentially resulting in remote code execution. SonicWall noted in its advisory that it has observed exploitation of both vulnerabilities, which suggests they have been chained in attacks. Advertisement. Scroll to continue reading. SMA1000 models 6210, 7210, and 8200v are affected by the zero-days. Hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions patch the vulnerabilities. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected. No details appear to be available on the attacks exploiting CVE-2026-83548 and CVE-2026-83549, and the vendor’s public advisory does not include indicators of compromise (IoCs). SonicWall product vulnerabilities are regularly exploited in the wild, including in ransomware attacks. Some security holes are exploited for weeks before they are patched. CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 17 SonicWall product flaws; CVE-2026-83548 and CVE-2026-83549 have not yet been added. Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform Related: Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities Related: SonicWall Urges Immediate Patching of Firewall Vulnerabilities Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs PaperCut Exploitation Escalates to Active IntrusionsNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product ExploitAnthropic Warns Claude Users of Infostealer Malware InfectionsBoston Scientific Still Recovering From CyberattackMore Details Emerge on Exploited PaperCut VulnerabilitiesHasbro Data Breach Exposed Employee Personal InformationATF Confirms Cyber Incident After Ransomware Group Claims AttackOpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Latest News Palo Alto Networks Acquires AI Agent Platform ConsoleSevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseCoast Guard Establishes Office of Maritime Cybersecurity PolicyExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data BreachCritical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fsonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F08\u002FSonicWall.jpg","2026-09-02T05:04:52+00:00","2026-09-02T06:00:26.77755+00:00",9,[18,21,24],{"name":19,"type":20},"SMA1000","product",{"name":22,"type":23},"SonicWall","vendor",{"name":25,"type":26},"SSL-VPN","technology","574f766a-fb3f-487c-8d2c-0720ae75471b",{"id":27,"icon":29,"name":30,"slug":31},null,"Zero-day","zero-day",[33,38,40,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":39},{"id":27,"icon":29,"name":30,"slug":31},{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55],{"type":52,"value":53,"context":54},"cve","CVE-2026-83548","Pre-authentication SSRF vulnerability in SMA1000 Appliance Work Place interface.",{"type":52,"value":56,"context":57},"CVE-2026-83549","OS command injection vulnerability in SMA1000 Appliance Management Console."]