Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Summary
SonicWall has released security updates to address two zero-day vulnerabilities in its SMA 1000 series VPN appliances that have already been exploited by attackers. One of the vulnerabilities, CVE-2026-83548, is a pre-authentication SSRF flaw with a critical CVSS score of 10.0.
IFF Assessment
The exploitation of critical zero-day vulnerabilities in VPN appliances poses a significant threat to organizations, allowing attackers to potentially compromise their networks and sensitive data.
Severity
The CVE-2026-83548 vulnerability is a pre-authentication SSRF flaw, meaning it can be exploited by an unauthenticated attacker over the network to make the appliance perform actions on their behalf, leading to a critical impact.
Defender Context
Defenders should prioritize patching their SonicWall SMA 1000 series appliances immediately due to the active exploitation of these zero-day vulnerabilities. This situation highlights the ongoing risk of supply chain attacks and the importance of staying vigilant against threats targeting widely used network infrastructure.