Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain Ravie LakshmananSep 02, 2026Vulnerability / Network Security SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below – CVE-2026-83548 (CVSS score: 10.0) – A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549 (CVSS score: 7.8) – A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker…
CVEs: CVE-2026-83548, CVE-2026-83549, CVE-2026-15409, CVE-2026-15410
Original source: thehackernews.com