11h ago · bleeping-computer
SonicWall has warned of an actively exploited zero-day vulnerability chain affecting its SMA1000 appliances, involving two critical command injection flaws. The first vulnerability (CVE-2026-83548) is a server-side request forgery (SSRF) in the WorkPlace interface, while the second (CVE-2026-83549) allows command injection in the Management Console by authenticated administrators. These vulnerabilities enable remote code execution, and attackers are actively exploiting them in the wild. Customers are urged to apply hotfixes immediately, though specific IOCs have not been released by SonicWall.