Home / Sep 03, 2026 / Story
0
#2 The Hacker News general September 02, 2026 at 10:53 UTC

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

By [email protected] (The Hacker News)

AI Summary

SonicWall has patched two zero-day vulnerabilities in its SMA 1000 series VPN appliances — CVE-2026-83548 (CVSS 10.0, pre-auth SSRF) and CVE-2026-83549 — that threat actors are actively chaining to achieve unauthenticated remote code execution. Discovered internally by SonicWall's William Perry and Adam Babis, these follow earlier zero-day attacks on the vendor's edge devices this summer. SMA 1000 appliances are widely deployed as enterprise remote access gateways, making prompt patching critical.

Relevance score: 90.0/100

# More from September 03