Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Overview
SonicWall has issued security updates to fix two serious vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series VPN appliances. These flaws, identified as CVE-2026-83548 and another not specified in the article, have already been exploited in zero-day attacks. The first vulnerability, CVE-2026-83548, has a maximum severity score of 10.0 and allows attackers to execute server-side request forgery (SSRF) attacks before authentication. This means that unauthorized users could potentially access sensitive internal resources. Organizations using these VPN appliances are urged to apply the updates immediately to protect their systems from potential exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
- Action Required: SonicWall has released security updates to address the vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance
Impact
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
SonicWall has released security updates to address the vulnerabilities. Users should apply these updates as soon as possible to mitigate the risk of exploitation.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Zero-day, Exploit, and 1 more.