CRITICAL: SonicWall SMA 1000 CVE-2026-83548 Exploited in the Wild
SonicWall confirmed active exploitation of two SMA 1000 zero-days, a CVSS 10.0 pre-authentication SSRF tracked as CVE-2026-83548 and a post-authentication command injection tracked as CVE-2026-83549. Attackers appear to be chaining the pair for remote code execution on internet facing SSL VPN appliances, and hotfixes are available now.