SONICWALL disclosed two critical vulnerabilities in its SMA1000 series appliances, specifically **CVE-2026-83548** (a pre-authentication SSRF flaw) and **CVE-2026-83549** (a post-authentication OS command injection flaw). These vulnerabilities are actively being exploited and require immediate action from affected users to upgrade to patched versions. SonicWall's advisory provides specific affected and fixed versions (12.4.3-03526 and 12.5.0-02952).
Organizations should also monitor for indicators of compromise and restrict remote access until systems can be upgraded. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating remediation by September 5, 2026.