Exploited in the wild SonicWall SMA 1000 Appliances zero-day SonicWall network-edge
SonicWall SMA 1000 appliances under attack via zero-day flaws
CVE Tools coverage
SonicWall has verified that attackers are actively leveraging two newly disclosed flaws, identified as CVE-2026-83548 and CVE-2026-83549, against its SMA 1000 line of secure remote access appliances. The first issue is a pre-authentication server-side request forgery vulnerability, while the second allows administrators to execute remote code through OS command injection in the management console. Affected hardware includes physical models 6210 and 7210, as well as the virtual 8200v instance, whereas SMA 100 devices and other SonicWall firewalls remain unaffected. Given the critical nature of the risk, the vendor advises organizations to deploy the available emergency hotfix without delay and to perform a thorough compromise assessment.