# SonicWall confirms exploitation of two SMA 1000 flaws

_Wednesday, September 2, 2026 at 6:13 AM EDT · Security · Latest · Tier 1 — Major_

![SonicWall confirms exploitation of two SMA 1000 flaws — Primary](https://img.helpnetsecurity.com/wp-content/uploads/2026/07/14165048/sonicwall-1500.webp)

SonicWall confirmed active exploitation of two previously undisclosed vulnerabilities in SMA 1000 secure remote-access appliances, according to Help Net Security. CVE-2026-83548 is a pre-authentication server-side request forgery flaw that can let remote unauthenticated attackers access sensitive functionality and perform unauthorized operations. CVE-2026-83549 is an OS command-injection flaw that can enable remote code execution for authenticated administrators in specific conditions. SonicWall urged customers to apply its hotfix and review systems for compromise.

## Sources

- [Help Net Security](https://www.helpnetsecurity.com/2026/09/02/sonicwall-sma-1000-cve-2026-83548-cve-2026-83549-zero-day-attacks/)

---
Canonical: https://techandbusiness.org/newswire/wibavpyIQPYX_F-qGW6lrI
Retrieved: 2026-09-03T16:00:46.138Z
Publisher: Tech & Business (techandbusiness.org)
