Threat Intelligence

SonicWall Patches Two Zero-Day Flaws in SMA 1000 VPN Appliances Actively Exploited by Attackers

The Hacker News · 2 Sept 2026
Key Takeaway If your business uses SonicWall SMA 1000 series VPN appliances, apply the latest security updates immediately and review remote access logs for signs of suspicious activity.

SonicWall has released security updates for two vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series VPN appliances, which are used by businesses to provide secure remote access to internal networks. Both flaws were discovered internally by SonicWall researchers and have already been exploited in real-world attacks before patches were available, making them zero-day vulnerabilities.

The more severe of the two, tracked as CVE-2026-83548, carries the maximum possible severity score of 10.0. It is a pre-authentication server-side request forgery (SSRF) flaw, meaning an attacker doesn't need valid login credentials to exploit it. Security researchers believe this flaw may be combined with the second vulnerability to form a more damaging attack chain, potentially allowing intruders to gain deeper access into affected systems.

Because SMA 1000 appliances sit at the edge of corporate networks and control remote access, a successful exploit could give attackers a foothold to move further into an organisation's systems, steal data, or deploy additional malware. SonicWall has not detailed the full scope of exploitation but confirmed active attacks are underway, underscoring the urgency of applying the available fixes.

SonicWall VPN Security Zero-Day Vulnerability Remote Access Patch Management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.