SonicWall urges immediate patching as critical zero-day vulnerabilities are actively exploited.

CVE-2026-83548 targets the SMA1000 Work Place interface with pre-authentication SSRF, while CVE-2026-83549 targets the Appliance Management Console and requires authentication for OS command injection.
CVE-2026-83548 is rated CVSS v3.1 10.0 (Critical) and CVE-2026-83549 is rated CVSS v3.1 7.8 (High), according to vendor advisories.
Security researchers report the flaws are being actively exploited in the wild and attackers are chaining the two CVEs to reach privileged functionality and potentially harvest credentials or move laterally.
NHS England and other advisories warn of an increasing risk to internet-facing edge devices and note there are no workarounds; immediate patching and aggressive remediation are advised.
Two chained zero-day vulnerabilities in SonicWall SMA1000 remote access appliances are under active attack, according to CyberScoop. The flaws let attackers bypass authentication and execute commands on devices that sit at the network edge, potentially giving them a foothold into entire enterprises. SonicWall has released emergency patches and is urging customers to update immediately.
CVE-2026-83548 carries a critical CVSS score of 10.0 and allows unauthenticated attackers to access restricted functions via SSRF attacks, NetworkWorld reports. The second flaw, CVE-2026-83549, requires login but leads to OS command injection with a CVSS score of 7.8. The affected models are SMA1000 6210, 7210, and 8200v.
The first vulnerability, CVE-2026-83548, targets the SMA1000 Workplace interface and lets attackers craft SSRF requests without logging in. CISA added both flaws to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Attackers then chain this into CVE-2026-83549, which allows authenticated users to inject OS commands into the Appliance Management Console.
This two-step attack is dangerous because SMA1000 appliances control remote access for thousands of employees. Once compromised, attackers can harvest credentials, spy on traffic, and move laterally into the internal network. Security researchers stress that defenders must patch both flaws together—fixing only one leaves enterprises vulnerable.
SonicWall has released hotfix firmware versions 12.4.3-03526 and 12.5.0-02952 to patch both CVEs, CSO Online reports. The company warns there are no workarounds—patching is the only mitigation. Customers should apply updates to all SMA1000 models immediately, especially those exposed to the internet.
If signs of compromise appear—unusual logins, configuration changes, or unexpected traffic—SonicWall advises aggressive remediation. This includes reimaging or redeploying appliances, resetting all credentials, and rotating TOTP tokens. NHS England has also flagged rising attacks on edge devices and echoes the urgency of immediate action.
This is not SonicWall's first brush with zero-day attacks. The SMA1000 product line has been hit repeatedly over the past years, earning it a reputation as a frequently targeted gateway. Each vulnerability adds risk because patches lag real-world exploitation.
Security analysts warn that enterprises relying on older SonicWall models face compounding exposure. The combination of pre-auth and post-auth flaws means a single attacker can escalate from network boundary to full system control. Organizations must prioritize SonicWall inventory discovery and patch validation across all branches and remote sites.
Publishers
24
Articles
6
Reach
30