SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
Attackers are actively exploiting two zero-day vulnerabilities in specific SonicWall SMA 1000 models, allowing for unauthenticated remote code execution when the flaws are chained together. The issues include a critical pre-authentication server-side request forgery vulnerability (CVE-2026-83548, CVSS 10.0) and a post-authentication OS command injection flaw (CVE-2026-83549, CVSS 7.8). SonicWall advises customers running versions 12.4.3-03453 or 12.5.0-02835 on models 6210, 7210, and 8200v to immediately update to firmware versions 12.4.3-03526 or 12.5.0-02952. Organizations should also monitor for indicators of compromise and consider reimaging or redeploying appliances if breaches are detected.