importantSYS.SOURCE: The Hacker News• 2026-09-02T16:23:49+05:30
SonicWall SMA 1000 Zero-Day Exploits Enable Remote Code Execution via Attack Chain
Attackers are exploiting two zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances to execute arbitrary code through an attack chain. The flaws affect specific models and versions, with recommended upgrades and security remediation steps for affected organizations.
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below -
CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance
*** END OF TRANSMISSION ***