< Back to all clusters
[TECHNOLOGY] · 8 sources

started · updated

SonicWall SMA 1000 appliances targeted by active zero-day exploits

SonicWall has confirmed that attackers are actively exploiting two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. The flaws affect physical and virtual models 6210, 7210, and 8200v.

The first vulnerability, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) with a critical CVSS rating of 10.0. It allows unauthenticated remote attackers to gain unauthorized access to sensitive functions. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability (CVSS 7.8) in the Appliance Management Console that can lead to remote code execution.

Security researchers suggest that attackers may be chaining these two vulnerabilities to fully compromise devices. SonicWall has released hotfixes for the affected firmware versions and strongly urges customers to apply them immediately. For devices suspected of being compromised, the company recommends re-imaging or re-deploying the appliances, changing all administrative and user passwords, and resetting time-based one-time password (TOTP) tokens.

Entities

Adam Babis · CVE-2026-83548 · CVE-2026-83549 · SonicWall · William Perry

Claims

What the coverage asserts, and how many sources carry each claim.