Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

SonicWall SMA 1000 Under Attack via Chained Zero-Days

Published 2 September 2026

SonicWall is urging immediate action from customers using its SMA 1000 series secure remote access appliances, confirming that attackers are actively exploiting two newly disclosed zero-day vulnerabilities that can be chained together to achieve unauthenticated remote code execution. The company disclosed the flaws, CVE-2026-83548 and CVE-2026-83549, in an advisory published on September 1, 2026, stating its Product Security Incident Response Team had investigated cases indicating active exploitation in the wild. The more severe vulnerability, CVE-2026-83548, carries a maximum CVSS score of 10.0. It is a preauthentication server-side request forgery (SSRF) flaw located in the SMA 1000 Appliance Work Place interface, the user-facing portal. SonicWall explained the vulnerability stems from an unintended alternate access path. A remote, unauthenticated attacker could exploit this to gain unauthorized access to sensitive functionality and perform unauthorized operations. The second flaw, CVE-2026-83549, has a CVSS score of 7.8. It is a postauthentication remote code execution vulnerability in the SMA 1000 Appliance Management Console, the administrator portal.

0:00 / 0:00