SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

https://www.securityweek.com/wp-content/uploads/2025/08/SonicWall.jpg

SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild.

According to an advisory published by SonicWall on Tuesday, the vulnerabilities and their exploitation were discovered internally.

One of the flaws, tracked as CVE-2026-83548 with a CVSS score of 10, has been described as a pre-authentication SSRF issue in the Appliance Work Place interface of SMA1000 appliances. An attacker can exploit it remotely without authentication to access sensitive functionality and conduct unauthorized operations.

The second vulnerability, tracked as CVE-2026-83549 with a CVSS score of 7.8, is an OS command injection issue in the Appliance Management Console (AMC) component.

An authenticated attacker can exploit it to execute arbitrary OS commands, potentially resulting in remote code execution.

SonicWall noted in its advisorythat it has observed exploitation of both vulnerabilities, which suggests they have...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE