InfoSec News Nuggets – 09/04/2026
Brief
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
SonicWall is urging customers running its SMA1000 series secure remote access appliances to patch two zero-day vulnerabilities that have already been exploited in the wild, both discovered internally by the vendor. CVE-2026-83548 (CVSS 10.
- is a pre-authentication SSRF flaw in the Appliance Work Place interface that lets an unauthenticated attacker reach sensitive internal functionality, while CVE-2026-83549 (CVSS 7. 8) is an OS command injection flaw in the Appliance Management Console — Rapid7 notes the two can be chained together for fully unauthenticated remote code execution.
