SonicWall warned that attackers are chaining two newly discovered SMA1000 zero-days, CVE-2026-83548 and CVE-2026-83549, to achieve remote code execution on exposed appliances. The company urged immediate hotfixing and remediation steps as active exploitation has been confirmed against SMA1000 6210, 7210, and 8200v models. #SonicWall #SMA1000 #CVE-2026-83548 #CVE-2026-83549
Keypoints
- SonicWall confirmed active exploitation of two SMA1000 zero-day vulnerabilities.
- CVE-2026-83548 is a maximum-severity command injection flaw tied to SSRF.
- CVE-2026-83549 lets attackers with admin access run arbitrary OS commands.
- The issue affects SMA1000 6210, 7210, and 8200v devices, not SonicWall firewalls or SMA 100 Series.
- SonicWall urged customers to install the latest hotfix and re-image affected appliances if compromise is suspected.