CVE Tools
Back to feed
Exploited in the wild SMA1000 zero-day SonicWall rce

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

SonicWall has identified active exploitation of two zero-day vulnerabilities affecting its SMA1000 secure remote access gateways. The critical flaw, CVE-2026-83548, allows unauthenticated attackers to execute unauthorized operations via a server-side request forgery vulnerability in the Appliance Work Place interface. This is often paired with CVE-2026-83549, an authenticated OS command injection issue that can lead to full remote code execution within the management console.

SMA1000 models 6210, 7210, and 8200v are susceptible to these attacks. Administrators should apply hotfixes 12.4.3-03526 or 12.5.0-02952 immediately to mitigate the risk.