SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall has issued an urgent advisory stating that threat actors are actively exploiting a pair of zero-day vulnerabilities in its SMA1000 secure remote access appliances. The attack campaign chains a maximum-severity command injection flaw (CVE-2026-83548), caused by a server-side request forgery weakness, with a second command injection vulnerability (CVE-2026-83549) accessible to administrators with valid credentials. This combination allows attackers to achieve remote code execution on affected devices.
The vulnerabilities impact SMA1000 models 6210, 7210, and 8200v, while SSL-VPN services on other SonicWall firewalls and the SMA 100 Series remain unaffected. SonicWall strongly urges customers to apply the available hotfix release immediately to mitigate these risks.