SonicWall SMA1000 Zero-Days Exploited in Attacks
SonicWall confirms active exploitation of two SMA1000 zero-days: CVE-2026-83548 (pre-auth SSRF) and CVE-2026-83549 (OS command injection). Chained, they enable unauthenticated RCE.

Two zero-days in SonicWall’s SMA1000 remote access appliance are under active exploitation. Confirmed by the vendor on September 1, 2026. Chained together, the flaws enable unauthenticated remote code execution.
CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the SMA1000 Workplace interface. An unintended alternate access path allows a remote, unauthenticated attacker to reach internal functionality and perform unauthorized operations. Confidence: confirmed, per the SonicWall advisory and NVD entry.
CVE-2026-83549 is an OS command injection flaw in the SMA1000 Appliance Management Console (AMC). CVSS 7.8, severity HIGH per NVD. In isolation it requires administrator credentials. Chained with CVE-2026-83548, that access-control boundary is the vector under active attack. Confidence: confirmed.
The chain: the SSRF (CVE-2026-83548) provides an unauthenticated path to reach the AMC, enabling exploitation of the command injection (CVE-2026-83549) and resulting in arbitrary OS command execution.
Exploitation timeline: active as of September 1, 2026. No threat actor attribution confirmed at this time. SonicWall recommends immediate patching; consult the vendor advisory for affected firmware versions and patch availability.
SMA1000 is an enterprise SSL VPN and remote access gateway. It has been a sustained target across 2026: CISA previously flagged ransomware operators actively exploiting SMA1000 in August and Volexity linked earlier SMA1000 zero-days to threat group UTA0533 in July.
Source: SecurityWeek, NVD records for CVE-2026-83548 and CVE-2026-83549.
- [ HIGH ]CVE-2026-83548Pre-auth SSRF in SonicWall SMA1000 Workplace Interface
- [ HIGH ]CVE-2026-83549OS Command Injection in SonicWall SMA1000 AMC
Found this useful? Share it.


