Sep 3
/
Latest News
Jack Henry Confirms Corporate Network Breach via Vishing Attack; Data from 10 Client Banks Exposed
SonicWall has confirmed that attackers are actively exploiting two previously undisclosed vulnerabilities in its SMA 1000 remote access appliances, prompting urgent guidance for customers to apply hotfixes and review systems for compromise.
The flaws, tracked as CVE‑2026‑83548 and CVE‑2026‑83549, affect both physical and virtual SMA 1000 models — 6210, 7210, and 8200v — but do not impact SMA 100 appliances or SonicWall firewalls. According to SonicWall, the vulnerabilities were discovered internally and have already been used in real‑world attacks.
CVE‑2026‑83548 is a critical pre‑authentication server‑side request forgery (SSRF) vulnerability in the Appliance Work Place interface. It allows remote, unauthenticated attackers to access sensitive functionality and perform unauthorized operations. CVE‑2026‑83549 is a post‑authentication OS command injection flaw in the Appliance Management Console that can enable remote code execution when exploited by an authenticated administrator.
SonicWall’s Product Security Incident Response Team said it has investigated a case indicating active exploitation and “strongly urged” customers to deploy the provided hotfixes immediately. Organizations are also advised to contact SonicWall Technical Support to review systems for indicators of compromise. If compromise is confirmed, SonicWall recommends re‑imaging hardware appliances or redeploying virtual ones, changing all user and administrator passwords, and resetting TOTP tokens.
The company has not released indicators of compromise or further details about the attacks, but SMA 1000 appliances have been repeatedly targeted via zero‑day vulnerabilities in recent years, including incidents in late 2025 and mid‑2026.
The flaws, tracked as CVE‑2026‑83548 and CVE‑2026‑83549, affect both physical and virtual SMA 1000 models — 6210, 7210, and 8200v — but do not impact SMA 100 appliances or SonicWall firewalls. According to SonicWall, the vulnerabilities were discovered internally and have already been used in real‑world attacks.
CVE‑2026‑83548 is a critical pre‑authentication server‑side request forgery (SSRF) vulnerability in the Appliance Work Place interface. It allows remote, unauthenticated attackers to access sensitive functionality and perform unauthorized operations. CVE‑2026‑83549 is a post‑authentication OS command injection flaw in the Appliance Management Console that can enable remote code execution when exploited by an authenticated administrator.
SonicWall’s Product Security Incident Response Team said it has investigated a case indicating active exploitation and “strongly urged” customers to deploy the provided hotfixes immediately. Organizations are also advised to contact SonicWall Technical Support to review systems for indicators of compromise. If compromise is confirmed, SonicWall recommends re‑imaging hardware appliances or redeploying virtual ones, changing all user and administrator passwords, and resetting TOTP tokens.
The company has not released indicators of compromise or further details about the attacks, but SMA 1000 appliances have been repeatedly targeted via zero‑day vulnerabilities in recent years, including incidents in late 2025 and mid‑2026.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.