SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.

The vulnerabilities, discovered internally by SonicWall’s William Perry and Adam Babis, are listed below –

CVE-2026-83548 (CVSS score: 10.0) –  A pre-authentication SSRF vulnerability in the Appliance