SonicWall says two SMA1000 flaws, CVE-2026-83548 and CVE-2026-83549, have been exploited in the wild on internet-facing secure remote access gateways and SSL-VPN appliances. The vendor says it found the bugs and the attacks internally, and the affected models include 6210, 7210, and 8200v.
The first flaw is a pre-auth server-side request forgery (SSRF): it lets an attacker make the appliance send privileged internal requests without logging in. The second is a command-injection bug in the Appliance Management Console that can turn a management action into operating-system commands. Chained together, they let an attacker reach unauthenticated remote code execution on the gateway, and SonicWall did not publish indicators of compromise.
That leaves exposed SMA1000 appliances as immediate takeover targets, not just login fronts. If one sits between users and internal services, a compromise can put the gateway itself under attacker control before normal indicator-based hunting has anything to grab onto.