securityaffairs.com 9/2/2026, 3:37:21 PM · external

SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

SONICWALL has patched two critical zero-day vulnerabilities in its SMA 1000 VPN appliances that are actively being exploited. The vulnerabilities are: 1) **CVE-2026-83548** (CVSS 10.0) - a pre-authentication SSRF flaw allowing remote attackers to access sensitive functionality; 2) **CVE-2026-83549** (CVSS 7.8) - a post-authentication command injection flaw allowing authenticated attackers to execute arbitrary commands. SonicWall advises customers to upgrade to the latest hotfix and check for any signs of compromise to enhance security across affected models.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline