Security researchers warn that hackers are chaining a maximum-severity vulnerability in the SonicWall SMA1000 appliances with a high-severity flaw to achieve remote code execution.
A critical server-side request forgery flaw in the Appliance Work Place interface, tracked as CVE-2026-83548, allows an attacker to access sensitive functions and perform unauthorized actions. The vulnerability has a severity score of 10, the maximum on the scale.
That vulnerability is being chained with CVE-2026-83549, a high-severity OS command-injection vulnerability in the Appliance Management Console. The vulnerability has a severity score of 7.8.
SonicWall on Tuesday confirmed the flaws are being exploited in the wild and urged all users to upgrade to the latest hotfix.
The Cybersecurity and Infrastructure Security Agency on Wednesday added CVE-2026-83548 and CVE-2026-84549 to the Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies have until Saturday to mitigate the vulnerabilities.
Rapid7 researchers noted that SonicWall SMA appliances are often used in environments where workers and other authorized parties have secure access to internal applications and resources. Appliance Work Place applications are often exposed to the public internet in these environments.
The current exploitation activity comes less than two months after SonicWall SMA1000 appliances were targeted in July. Researchers at Volexity traced exploitation of CVE-2026-15409 and CVE-2026-15410 to threat activity that began in June.
Volexity researchers tracked that activity to an actor it identified as UTA0533. Researchers have not linked the current activity to a specific threat group.