7h ago · hacker-news
SonicWall has identified and patched two zero-day vulnerabilities in its SMA 1000 series VPN appliances that are being actively exploited. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, can be chained together to enable remote unauthenticated attackers to gain unauthorized access and execute arbitrary commands on affected systems. The attack impacts specific versions of the SMA 1000 models 6210, 7210, and 8200v, and SonicWall advises customers to upgrade immediately, check for indicators of compromise, and reset credentials and TOTP if compromised.