Exploitation of Zero-Day Vulnerabilities in SonicWall SMA1000 Series Appliances
Two zero-day vulnerabilities could be chained together to allow an unauthenticated attacker to perform RCE
Summary
Two zero-day vulnerabilities could be chained together to allow an unauthenticated attacker to perform RCE
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-83548 and CVE-2026-83549
SonicWall has stated that it has investigated a case indicating the active exploitation of these vulnerabilities. SonicWall strongly urges customers to update to the relevant hotfix release as soon as possible to remediate these vulnerabilities.
Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain.
Introduction
SonicWall has released a security advisory to address two zero-day vulnerabilities affecting SMA1000 series appliances.
- CVE-2026-83548 is a server-side request forgery (SSRF) vulnerability with a CVSSv3 score of 10.0. A remote unauthenticated attacker could exploit this vulnerability to gain unauthorised access to sensitive functionality and perform unauthorised operations.
- CVE-2026-83549 is a command injection vulnerability with a CVSSv3 score of 7.8. A remote attacker authenticated as administrator could exploit this to execute arbitrary OS commands, resulting in remote code execution (RCE).
Remediation advice
Affected organisations must review SonicWall's security advisory SNWLID-2026-0016 and apply the relevant updates as soon as possible.
If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected].
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Organisations must patch to a fixed version:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 |
| Guidance |
Recommended: Contact SonicWall Technical Support for assistance reviewing the system for indicators of compromise (IoCs). If IOCs are detected on the system, SonicWall recommends that organisations:
If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 2 September 2026 10:41 am