Cybersecurity Research

Critical SonicWall Flaws Under Active Attack: Patch Now

Sophos · 2 Sept 2026
Key Takeaway If your business uses SonicWall SMA1000 appliances, check your model and firmware version immediately and apply the vendor's update as soon as possible, as attackers are already exploiting these flaws.

SonicWall has disclosed two security flaws affecting its SMA1000 series appliances (models 6210, 7210, and 8200v) that are used for secure remote access. The first, CVE-2026-83548, is a critical vulnerability rated 10.0 out of 10 on the severity scale. It allows an attacker with no login credentials to abuse the appliance's Work Place interface to gain unauthorized access and perform actions they should not be able to.

The second flaw, CVE-2026-83549, is rated high severity and affects the Appliance Management Console. It could let an attacker who already has administrator-level access run arbitrary commands on the device, potentially taking full control of it.

SonicWall has confirmed that both vulnerabilities are being actively exploited by attackers right now, making this an urgent issue rather than a theoretical risk. Security researchers at Sophos are urging all organisations using these appliances to check whether they are running affected versions and apply available updates without delay. Sophos has stated it continues to monitor for related attack activity and will roll out further protections as they become available.

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.