Friday, Sep 4, 2026
1 SonicWall Patches CVSS 10.0 SMA 1000 Zero Day, Worst Flaw in 9 Month Wave↩︎ 🔒 Cybersecurity Sep 4, 10:30 AM EDT 6/5
Attackers are using a chain of two vulnerabilities in SonicWall SMA 1000 appliances to achieve unauthenticated remote code execution. One of the flaws carries a CVSS score of 10.0, the highest possible severity rating, while the other allows remote code execution for authenticated users. The security vendor released fixes for CVE-2026-83548 and CVE-2026-83549 on Tuesday alongside an official disclosure of the zero day threats.
The Cybersecurity and Infrastructure Security Agency added both defects to its known exploited vulnerabilities catalog on September 2 as part of a seven item update. Federal agencies must now meet remediation deadlines under Binding Operational Directive 26-04 to secure the affected hardware. The SMA 1000 product line has faced recurring security defects and active attacks over the last nine months.