TWO newly disclosed vulnerabilities in SonicWall SMA 1000 devices are reported to be exploited in the wild, enabling attackers to chain three flaws for remote code execution. The security write-up identifies two CVEs, CVE-2026-83548 and CVE-2026-83549, both rated “Exploited in the wild” with high CVSS scores, and notes that a public Metasploit exploit module has been released.
The attacker chain begins with a pre-authentication server-side request forgery in the Appliance Work Place interface, proceeds to undocumented read/write access on the internal CouchDB, and culminates in an operating-system command injection in the Appliance Management Console, granting full root access.
Affected hardware and firmware include the SMA 1000 models 6210, 7210, and 8200v, with vulnerable firmware releases described as platform hotfix version 12.4.3-03453 and older, and version 12.5.0-02835 and older. SonicWall advises upgrading to hotfixes 12.4.3-03526 or 12.5.0-02952 and reviewing logs for indicators of compromise, with a full re-imaging or redeployment if a breach is suspected.
The article emphasises that the public disclosure of exploit code raises risk for unpatched deployments and that active exploitation has been observed, urging immediate application of vendor advisories.