SonicWall Patches Two VPN Zero-Days Already Being Used by Hackers

A perfect-10 flaw in SonicWall's SMA 1000 remote-access boxes lets attackers slip past the login screen, and it's being paired with a second bug in real attacks.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial 16:9 image of a bank of dark server rack hardware in a dimly lit data center, with a single orange warning indicator light glowing on o
Share

Key points

  • SonicWall issued emergency fixes for two flaws in its SMA 1000 series VPN appliances, kit that lets staff log into company networks from home.
  • One of the bugs, CVE-2026-83548, scores the maximum 10.0 on the industry severity scale and needs no password to exploit.
  • Both flaws are already being used in live attacks, according to SonicWall's own advisory.
  • The bugs were found in-house by SonicWall researchers William Perry and Adam Babis.
  • Administrators are urged to patch immediately; the SMA 1000 line is popular with mid-sized companies and government agencies.

SonicWall has shipped fixes for two serious flaws in its Secure Mobile Access 1000 appliances, the physical and virtual boxes that businesses use to give remote workers a secure tunnel into the office network. The vendor confirms both flaws are being exploited in the wild.

That means the patches are not theoretical. Someone is already using them.

The more serious of the pair, CVE-2026-83548, carries a CVSS score of 10.0. CVSS is the standard 0-to-10 rating used across the industry, and a 10 is as bad as it gets. The flaw is a pre-authentication server-side request forgery, or SSRF, which in plain English means an unauthenticated attacker can trick the appliance into making network requests on their behalf, no username or password required.

The second bug has not been detailed publicly at the time of writing, but SonicWall says the two can be strung together into an attack chain, where one flaw opens the door and the next walks through it.

Both were discovered internally by SonicWall's William Perry and Adam Babis. First reported by The Hacker News, the disclosure lands with the vendor's advisory as the primary source.

What is actually affected?

The SMA 1000 series only. These are the higher-end remote-access appliances SonicWall sells to larger organisations. The smaller SMA 100 line, common in small businesses, is a separate product with its own patch cycle and is not named in this advisory.

Detail Value
Lead CVE CVE-2026-83548
CVSS score 10.0 (critical)
Flaw type Pre-auth SSRF
Affected product SonicWall SMA 1000 series
Exploited in the wild Yes, per vendor
Credited researchers William Perry, Adam Babis (SonicWall)

Should ordinary users be worried?

Not directly, but your employer might be. If your company uses a SonicWall VPN to let you work from home, the IT team needs to install the patch quickly. For everyone else, this is a corporate infrastructure issue, not something sitting on your phone or laptop.

Hackers targeting VPN appliances is a well-worn pattern. Break the front door of the remote-access box and you often land inside the corporate network with a useful vantage point. That's why a pre-authentication flaw with a 10.0 rating on a VPN product is treated as a drop-everything problem by defenders.

What should administrators do now?

Apply the SonicWall update for the SMA 1000 series today, not next maintenance window. Then check the appliance logs for signs of exploitation going back several weeks, because zero-day means attackers had a head start before the patch existed.

If a device cannot be patched immediately, restrict its management interface to known IP addresses and pull it off the public internet where possible. SonicWall's advisory is the source of truth for exact fixed versions and any interim mitigations (worth reading it directly rather than relying on secondary summaries).

Expect exploit code to appear publicly within days. It usually does, once a 10.0 pre-auth bug is confirmed exploited.

© 2026 Threat Vectr