SonicWall SMA 1000 zero-day exploited for unauthenticated takeover
SonicWall disclosed two critical vulnerabilities in its SMA 1000 appliance, including a pre-auth SSRF (CVE-2026-83548) and a post-auth RCE (CVE-2026-83549). Chained together, they allow unauthenticated remote code execution, and active exploitation has been observed.
The disclosed flaws affect the SMA 1000 series, a high-end secure access gateway used by enterprises to provide remote connectivity. The first issue, a pre-authentication server-side request forgery, lets an attacker reach internal resources without credentials. The second, a post-authentication remote code execution, requires a valid session but becomes dangerous when chained with the first. Because the chain yields unauthenticated takeover, any exposed appliance is at immediate risk. SonicWall has confirmed active exploitation, meaning threat actors are already leveraging the combination in the wild. Organizations running SMA 1000 devices should treat this as an urgent patch priority, as the attack surface is internet-facing and the impact is full system compromise.
This story could affect any enterprise relying on SonicWall SMA 1000 for remote access, including IT teams, remote workers, and the data they handle. If exploited, attackers may gain full control of the gateway, potentially moving laterally into internal networks, exfiltrating sensitive information, or deploying ransomware. The confirmed active exploitation raises the stakes, as unpatched devices may already be compromised. Smaller organizations without dedicated security staff could be especially vulnerable, facing downtime and recovery costs. The incident also underscores how chained vulnerabilities in network edge devices can turn a single flaw into a critical, wide-reaching threat.