Jessica Entwistle
September 2 2026
SonicWall has disclosed two zero-day vulnerabilities in its SMA1000 series SSL VPN appliances, CVE-2026-83549 and CVE-2026-83548, which are being actively exploited in the wild. SecurityWeek reports that the flaws can be chained together to achieve unauthenticated remote code execution on affected devices. SonicWall has released patches and is urging customers to update immediately. The vulnerabilities affect widely deployed appliances used by organisations for secure remote access to corporate networks.
SSL VPN appliances sit at the network perimeter and provide direct access to internal systems, making them high-value targets for attackers. The fact that these vulnerabilities are already being exploited in the wild, and can be chained to achieve unauthenticated remote code execution, means that organisations running vulnerable SMA1000 devices are at immediate risk of network compromise. Attackers who successfully exploit these flaws can gain a foothold inside the network, move laterally to other systems, and exfiltrate data. The absence of an authentication requirement significantly lowers the barrier for exploitation. For UK businesses using SonicWall SMA1000 appliances, this is not a theoretical risk but an active threat that requires urgent attention.
Organisations should immediately verify the patch status of all SonicWall SMA1000 appliances and apply the latest updates as a priority. Review access logs and administrative activity for any signs of compromise, particularly focusing on unusual login attempts, configuration changes or unexpected administrative sessions since late August. If patching cannot be completed immediately, consider temporary mitigations such as restricting access to the management interface, placing devices behind additional network controls, or implementing stricter firewall rules until updates are applied. Ensure that the process for identifying, prioritising and deploying patches for perimeter devices is clearly defined and regularly tested. This incident is also a prompt to review whether remote access infrastructure is appropriately monitored and whether alerting is in place to detect anomalous activity on VPN appliances.
Source: SecurityWeek