Published Thursday, September 03, 2026 at 10:53 AM PT

<strong>BREAKING: SonicWall SMA 1000 Zero-Days Actively Exploited β€” Patch Immediately</strong>

BLUF: Two unpatched zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in SonicWall Secure Mobile Access (SMA) 1000 series appliances are being actively exploited in the wild. SonicWall has released emergency patches. All organizations running affected SMA 1000 appliances must apply updates within 24 hours.

DETAILS:

  • CVE-2026-83548 and CVE-2026-83549 β€” Two distinct zero-day flaws in SonicWall SMA 1000 series appliances; both confirmed under active exploitation in production environments.
  • Affected product and scope β€” Secure Mobile Access (SMA) 1000 Appliance Workplace and Appliance Management modules (full component surface area not yet detailed in available source).
  • Threat confirmation β€” Active exploitation confirmed; not hypothetical or proof-of-concept only.
  • Patch availability β€” SonicWall has released emergency security updates; patch links and version requirements available from SonicWall support portal (build/version specifics not included in this alert).

IMPACT:

  • Who is affected β€” All organizations deploying SonicWall SMA 1000 appliances for remote access, VPN gateway, or appliance administration worldwide.
  • Attack surface β€” SMA 1000 is a remote access gateway; exploitation could grant attackers unauthorized access to corporate VPNs, remote workers, or administrative console β€” potential lateral network entry point.
  • Scope and severity β€” Widespread deployment in enterprise environments; active exploitation raises urgency to critical.

RECOMMENDED ACTIONS:

  • Next 24 hours: Identify all SonicWall SMA 1000 appliances in your environment and confirm current firmware version.
  • Immediate patching: Apply SonicWall’s emergency update to all affected appliances. Consult SonicWall security advisories for version compatibility and rollback procedures.
  • Monitoring: Review SMA 1000 appliance logs for unauthorized Workplace/Management access, failed administrative logins, or unexpected configuration changes dating back 7+ days.
  • Temporary mitigation (if patching delayed): Restrict administrative/Workplace access to known-good source IPs; consider taking non-critical SMA 1000 instances offline if patching cannot be completed quickly.

SOURCES:

  • SOC Prime β€” CVE-2026-83548 and CVE-2026-83549 (SonicWall SMA 1000 Zero-Days Exploited in the Wild)

Recent high-severity events at publish time:

Recent high-severity events