SonicWall warns of actively exploited SMA1000 zero-day flaws
What happened
SonicWall disclosed that threat actors are actively chaining two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, to execute remote code on SMA1000 appliances. The attack exploits a server-side request forgery flaw in the WorkPlace interface and a command injection vulnerability in the Management Console to gain unauthorized control over the devices.
Why it ranks #1
SonicWall disclosed that threat actors are actively chaining two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, to execute remote code on SMA1000 appliances by exploiting a server-side request forgery flaw in the WorkPlace interface and a command injection vulnerability in the Management Console.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
Re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise are detected.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited