Exploited in the wild SonicWall SMA 1000 Series zero-day SonicWall network-edge
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
CVE Tools coverage
SonicWall has released patches for two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series, confirming active exploitation in the wild where attackers may be chaining the flaws together. The issues include a critical pre-authentication SSRF vulnerability, CVE-2026-83548 (CVSS score: 10.0), and a post-authentication command injection flaw, CVE-2026-83549 (CVSS score: 7.8), both of which can lead to unauthorized access or remote code execution. Users running versions prior to 12.4.3-03526 or 12.5.0-02952 on SMA 6210, 7210, and 8200v models are urged to upgrade immediately and check for indicators of compromise.