CVE Tools
Back to feed
Exploited in the wild SonicWall SMA 1000 zero-day SonicWall rce

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

Dark Reading·By Alexander Culafi··3 min read
CVE Tools coverage

Attackers are actively exploiting two zero-day vulnerabilities in specific SonicWall SMA 1000 models, allowing for unauthenticated remote code execution when the flaws are chained together. The issues include a critical pre-authentication server-side request forgery vulnerability (CVE-2026-83548, CVSS 10.0) and a post-authentication OS command injection flaw (CVE-2026-83549, CVSS 7.8).

SonicWall advises customers running versions 12.4.3-03453 or 12.5.0-02835 on models 6210, 7210, and 8200v to immediately update to firmware versions 12.4.3-03526 or 12.5.0-02952. Organizations should also monitor for indicators of compromise and consider reimaging or redeploying appliances if breaches are detected.