Attackers exploit zero-days in consistently besieged SonicWall product

Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall has disclosed and patched two actively exploited zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, in its SMA 1000 appliances after researchers said they could be chained to achieve unauthenticated remote-code execution. CISA added the flaws to its KEV catalog, while SonicWall urged customers to hunt for compromise, reimage affected devices if needed, and reset credentials and tokens. #SonicWall #SMA1000 #CVE-2026-83548 #CVE-2026-83549 #CISA #KEV

Keypoints

  • SonicWall patched two zero-days that were already being actively exploited.
  • The flaws can be chained for unauthenticated remote-code execution.
  • CISA added CVE-2026-83548 and CVE-2026-83549 to its KEV catalog.
  • SonicWall advised customers to check for indicators of compromise and reimage affected appliances if needed.
  • SonicWall devices have been repeatedly targeted by attackers, including ransomware groups like INC ransomware and Akira.

Read More: https://cyberscoop.com/sonicwall-sma1000-zero-days-actively-exploited/