SonicWall has released patches for two zero-day vulnerabilities in its SMA1000 series VPN appliances after confirming that attackers are already chaining the SMA1000 zero-day flaws together for unauthenticated remote code execution. The pair, tracked as CVE-2026-83548 and CVE-2026-83549, affect the Secure Mobile Access 1000 series, SonicWall’s line of enterprise remote-access gateways. Updates are available now.
What the SMA1000 zero-day flaws let attackers do
CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability in the appliance, and it carries the maximum possible CVSS score of 10.0. On its own, an SSRF bug lets an attacker make the appliance issue requests on their behalf, usually against internal services they couldn’t otherwise reach. That’s already bad, but the two flaws don’t stay separate: chained with CVE-2026-83549, they add up to full unauthenticated remote code execution, meaning no valid login and no user interaction are needed to run arbitrary code on the box. For a VPN gateway sitting at the network edge, that’s the worst category of bug there is, a direct line from an internet-facing service to code execution.
SonicWall has not published a technical breakdown of CVE-2026-83549 to match the detail available for its partner flaw. Public reporting so far covers the SSRF mechanism in CVE-2026-83548 thoroughly, CVSS score included, while the second CVE is described only by its role in the chain. Anyone trying to fingerprint this attack in their own logs is working with half the picture until SonicWall or a researcher fills that gap; the two NVD entries linked above are the authoritative record to check as it fills in.
Who found the bugs and what to do next
These weren’t reported by an outside researcher racing to disclose a live zero-day. The Hacker News reports the pair was found internally by SonicWall’s own William Perry and Adam Babis, which is a cleaner path to a fix than a public dump, but it doesn’t lower the urgency: SonicWall says both flaws are already being exploited, so the patch needs to go on before an administrator gets around to it, not after. SMA1000 appliances are typically deployed as the single front door for remote employee access, which makes them a high-value target and a costly place to fall behind on updates.
SonicWall’s edge appliances have drawn repeated attention from intrusion campaigns before, which is part of why a pre-auth, CVSS-10 SSRF chained to RCE moved fast across security coverage. If your organisation runs SMA1000 hardware, the immediate steps are applying the update and checking appliance access logs for requests that suggest the SSRF path was used before the patch landed.
What to watch
Watch for SonicWall or CISA guidance naming indicators of compromise: zero-days on edge appliances that are already being exploited tend to earn a Known Exploited Vulnerabilities catalogue entry once exploitation is confirmed at scale. Also worth watching is whether SonicWall eventually publishes a detailed writeup of CVE-2026-83549 to match CVE-2026-83548’s, since that gap is currently the biggest obstacle to understanding exactly how the chain runs end to end.








