CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5823

As cited

Copy frozen at (site build).

vulnerabilities

SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances

SonicWall disclosed two actively exploited zero-day vulnerabilities in SMA1000 remote access appliances that attackers chain together to achieve remote code execution. CVE-2026-83548, a critical pre-authentication server-side request forgery flaw in the Appliance Work Place interface (CVSS 10.0), is combined with CVE-2026-83549, a high-severity OS command injection in the Appliance Management Console (CVSS 7.8). The Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerability Catalog, with federal agencies required to patch by September 6, 2026.

Why it matters: Organizations operating SMA1000 6210, 7210, or 8200v models must apply the latest hotfix immediately; approximately 400 vulnerable devices are exposed online, and threat actors have demonstrated active exploitation in the wild.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances

SonicWall disclosed two actively exploited zero-day vulnerabilities in SMA1000 remote access appliances that attackers chain together to achieve remote code execution. CVE-2026-83548, a critical pre-authentication server-side request forgery flaw in the Appliance Work Place interface (CVSS 10.0), is combined with CVE-2026-83549, a high-severity OS command injection in the Appliance Management Console (CVSS 7.8). The Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerability Catalog, with federal agencies required to patch by September 6, 2026.

Why it matters: Organizations operating SMA1000 6210, 7210, or 8200v models must apply the latest hotfix immediately; approximately 400 vulnerable devices are exposed online, and threat actors have demonstrated active exploitation in the wild.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary