By Interestana AI Editorial — AI-drafted, human-overseen. How we report
SonicWall SMA 1000 Series Exploited Via Two Zero-Days

SonicWall has issued security updates to address two critical zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series VPN appliances, which have already been exploited by malicious actors. These vulnerabilities, identified internally by SonicWall's William Perry and Adam Babis, pose a significant risk to organizations relying on these devices for secure remote access. The first vulnerability, designated CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) flaw with a maximum CVSS score of 10.0, indicating critical severity. This means an attacker can exploit this vulnerability without needing to authenticate to the appliance, potentially allowing them to make unauthorized requests on behalf of the appliance to internal or external resources. The second vulnerability, CVE-2026-83549, is also a pre-authentication vulnerability, specifically an arbitrary code execution (ACE) flaw with a CVSS score of 9.0. This critical rating suggests that attackers can leverage this vulnerability to execute arbitrary code on the affected SMA 1000 series appliances, granting them a high level of control over the compromised system. The combination of these two vulnerabilities could potentially form an attack chain, where the SSRF vulnerability is used to gain initial access or gather information, followed by the ACE vulnerability to achieve full system compromise. SonicWall has not disclosed the specific attack chains observed in the wild but has emphasized the critical nature of these flaws. The company strongly advises all users of the SMA 1000 series appliances to apply the provided security updates immediately to mitigate the risk of exploitation. The SMA 1000 series appliances are designed to provide secure remote access to corporate networks, and their compromise could lead to unauthorized access to sensitive data, network disruption, and further downstream attacks. Organizations using these devices should also consider implementing additional security measures, such as network segmentation and intrusion detection systems, to enhance their overall security posture. The disclosure of these zero-day exploits highlights the ongoing threat landscape and the importance of proactive security patching and monitoring for critical infrastructure. SonicWall's swift response in releasing patches is a crucial step in protecting its customers, but vigilance remains paramount for all organizations facing sophisticated cyber threats. The specific details of the vulnerabilities and the recommended remediation steps are available in SonicWall's security advisory, which should be consulted by all affected users. The company's internal discovery of these flaws underscores the importance of robust internal security research and development efforts.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.