As cited
Copy frozen at (site build).
vulnerabilities
SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances
SonicWall disclosed two actively exploited zero-day vulnerabilities in SMA1000 remote access appliances that attackers chain together to achieve remote code execution. CVE-2026-83548, a critical pre-authentication server-side request forgery flaw in the Appliance Work Place interface (CVSS 10.0), is combined with CVE-2026-83549, a high-severity OS command injection in the Appliance Management Console (CVSS 7.8). The Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerability Catalog, with federal agencies required to patch by September 6, 2026.
Why it matters: Organizations operating SMA1000 6210, 7210, or 8200v models must apply the latest hotfix immediately; approximately 400 vulnerable devices are exposed online, and threat actors have demonstrated active exploitation in the wild.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances
SonicWall disclosed two actively exploited zero-day vulnerabilities in SMA1000 remote access appliances that attackers chain together to achieve remote code execution. CVE-2026-83548, a critical pre-authentication server-side request forgery flaw in the Appliance Work Place interface (CVSS 10.0), is combined with CVE-2026-83549, a high-severity OS command injection in the Appliance Management Console (CVSS 7.8). The Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerability Catalog, with federal agencies required to patch by September 6, 2026.
Why it matters: Organizations operating SMA1000 6210, 7210, or 8200v models must apply the latest hotfix immediately; approximately 400 vulnerable devices are exposed online, and threat actors have demonstrated active exploitation in the wild.
- Source published
- First seen by Cybersecurity Tracker