Skip to content
feed: live
>_0dayNews
sonicwall
● Breaking

SonicWall SMA1000 Zero-Days Exploited in Attacks

SonicWall confirms active exploitation of two SMA1000 zero-days: CVE-2026-83548 (pre-auth SSRF) and CVE-2026-83549 (OS command injection). Chained, they enable unauthenticated RCE.

SonicWall SMA1000 Zero-Days Exploited in Attacks
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Two zero-days in SonicWall’s SMA1000 remote access appliance are under active exploitation. Confirmed by the vendor on September 1, 2026. Chained together, the flaws enable unauthenticated remote code execution.

CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the SMA1000 Workplace interface. An unintended alternate access path allows a remote, unauthenticated attacker to reach internal functionality and perform unauthorized operations. Confidence: confirmed, per the SonicWall advisory and NVD entry.

CVE-2026-83549 is an OS command injection flaw in the SMA1000 Appliance Management Console (AMC). CVSS 7.8, severity HIGH per NVD. In isolation it requires administrator credentials. Chained with CVE-2026-83548, that access-control boundary is the vector under active attack. Confidence: confirmed.

The chain: the SSRF (CVE-2026-83548) provides an unauthenticated path to reach the AMC, enabling exploitation of the command injection (CVE-2026-83549) and resulting in arbitrary OS command execution.

Exploitation timeline: active as of September 1, 2026. No threat actor attribution confirmed at this time. SonicWall recommends immediate patching; consult the vendor advisory for affected firmware versions and patch availability.

SMA1000 is an enterprise SSL VPN and remote access gateway. It has been a sustained target across 2026: CISA previously flagged ransomware operators actively exploiting SMA1000 in August and Volexity linked earlier SMA1000 zero-days to threat group UTA0533 in July.

Source: SecurityWeek, NVD records for CVE-2026-83548 and CVE-2026-83549.

Related CVEs
  • [ HIGH ]CVE-2026-83548Pre-auth SSRF in SonicWall SMA1000 Workplace Interface
  • [ HIGH ]CVE-2026-83549OS Command Injection in SonicWall SMA1000 AMC

Found this useful? Share it.