SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices
SonicWall has issued an urgent security advisory warning that two previously unknown vulnerabilities in its SMA1000 series secure access appliances are being actively exploited in the wild. The flaws, tracked as CVE-2026-83549 and CVE-2026-83548, can be chained together to allow attackers to remotely execute code on affected devices without needing a username or password.
SMA1000 appliances are commonly used by organisations to provide secure remote access for employees, making them an attractive target for attackers looking to breach corporate networks. Because these devices sit at the network edge and often have limited monitoring, compromises can go unnoticed for extended periods while attackers establish deeper access.
SonicWall is urging customers to apply available patches or mitigations immediately and to review device logs for signs of suspicious activity. Given that exploitation is already occurring, organisations using SMA1000 devices should treat this as a high-priority issue rather than routine maintenance.