SonicWall SMA1000 zero-day chain enters KEV: patch and assess compromise
Published 10 Sep 2026 · Severity: critical
SonicWall confirms active exploitation of CVE-2026-83548 and CVE-2026-83549 in SMA1000 appliances. The chain combines pre-authentication SSRF with administrator-level command injection. Upgrade affected 6210, 7210 and 8200v appliances to the fixed hotfix, contact SonicWall for compromise review, and re-image or redeploy if indicators are found.