SONICWALL has reported two critical zero-day vulnerabilities affecting its SMA1000 series secure remote access gateway and SSL-VPN appliances. The vulnerabilities, CVE-2026-83548 (CVSS score 10) and CVE-2026-83549 (CVSS score 7.8), have been actively exploited. CVE-2026-83548 allows attackers to conduct unauthorized operations remotely without authentication via a pre-authentication SSRF flaw.
CVE-2026-83549 permits authenticated attackers to execute arbitrary OS commands, leading to potential remote code execution. SonicWall advises immediate patching for affected models (6210, 7210, 8200v) using designated hotfixes. Security issues with SonicWall products have been linked to ongoing ransomware attacks.