SonicWall has warned that hackers are actively exploiting two new zero-day vulnerabilities in its SMA1000 remote access appliances.
The flaws, tracked as CVE-2026-83548 and CVE-2026-83549, can be chained together to carry out remote code execution attacks. The first one affects the Appliance WorkPlace interface; the second impacts the Appliance Management Console and can allow attackers with administrator access to run operating system commands.
SonicWall said its security team has confirmed active exploitation and urged customers to install the latest hotfix as soon as possible.
The vulnerabilities affect SMA1000 6210, 7210, and 8200v models. SonicWall firewalls running SSL-VPN or the SMA 100 Series are not vulnerable.
SonicWall also recommends re-imaging affected devices, changing user and administrator passwords, and resetting TOTP tokens if signs of compromise are found. The company has yet to release details about the attacks or indicators of compromise.
Last month, two other SMA1000 flaws were exploited as zero-days to install malware, with US officials later warning that ransomware groups were abusing them.