SONICWALL has reported two new zero-day vulnerabilities in its SMA 1000 perimeter devices, leading to ongoing exploitation by attackers. The vulnerabilities, CVE-2026-83548 (pre-authentication SSRF) and CVE-2026-83549 (post-authentication RCE), affect models 6210, 7210, and 8200v. Users are urged to patch immediately, as the SSRF vulnerability was given a maximum CVSS score of 10.
SonicWall confirmed that these vulnerabilities are being actively exploited and advised customers to upgrade to specific firmware versions. Rapid7 indicated that these bugs could be chained for unauthenticated RCE. The advisory stresses the importance of re-imaging or re-deploying affected appliances if IOCs are found.