Security News

SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices

Security Week · 2 Sept 2026
Key Takeaway If your business uses SonicWall SMA1000 appliances, patch immediately and check logs for unusual activity, as attackers are already exploiting these flaws.

SonicWall has issued an urgent security advisory warning that two previously unknown vulnerabilities in its SMA1000 series secure access appliances are being actively exploited in the wild. The flaws, tracked as CVE-2026-83549 and CVE-2026-83548, can be chained together to allow attackers to remotely execute code on affected devices without needing a username or password.

SMA1000 appliances are commonly used by organisations to provide secure remote access for employees, making them an attractive target for attackers looking to breach corporate networks. Because these devices sit at the network edge and often have limited monitoring, compromises can go unnoticed for extended periods while attackers establish deeper access.

SonicWall is urging customers to apply available patches or mitigations immediately and to review device logs for signs of suspicious activity. Given that exploitation is already occurring, organisations using SMA1000 devices should treat this as a high-priority issue rather than routine maintenance.

SonicWall zero-day remote access vulnerability patch management

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.