SonicWall has warned customers that threat actors are actively exploiting two new zero-day vulnerabilities affecting its SMA1000 secure remote access appliances, according to BleepingComputer. The report says the flaws are being chained in remote code execution attacks against vulnerable systems. The first issue, CVE-2026-83548, is described by BleepingComputer as a maximum-severity command injection vulnerability in the SMA1000 Appliance WorkPlace interface. The report says it stems from a server-side request forgery weakness. The second issue, CVE-2026-83549, affects the SMA1000 Appliance Management Console. BleepingComputer reports that attackers with administrator privileges can exploit it to execute arbitrary operating system commands on vulnerable devices. The affected products are SonicWall SMA1000 6210, 7210, and 8200v models, according to the report. SonicWall’s advisory says the flaws do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Exposure is not theoretical. BleepingComputer cites internet security watchdog Shadowserver as tracking more than 400 SMA1000 appliances exposed online, while noting that some of those systems may already have been patched against the exploit chain. SonicWall is urging customers to upgrade physical or virtual SMA1000 appliances to the latest hotfix release as soon as possible. BleepingComputer also reports that SonicWall advised administrators to re-image appliances, change all user and administrator passwords, and reset time-based one-time password tokens if indicators of compromise are detected. The available public detail remains limited. BleepingComputer reports that SonicWall has not yet shared specifics about the ongoing attacks or published a list of indicators of compromise identified during its investigation. The warning follows other recent SMA1000 security incidents reported by BleepingComputer. In July, two other SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were exploited as zero-days for weeks to install custom malware on vulnerable VPN appliances; last month, the U.S. Cybersecurity and Infrastructure Security Agency confirmed that ransomware gangs had begun abusing those two flaws in the wild. SonicWall also warned customers in December to patch another SMA1000 zero-day, CVE-2025-40602, that attackers were chaining to gain root privileges. Who benefits: Defenders benefit from a clear product scope: SMA1000 6210, 7210, and 8200v are in scope, while SonicWall says firewall SSL-VPN and SMA 100 Series products are not affected. Attackers benefit from any exposed, unpatched SMA1000 systems still reachable online. Who's exposed: Organizations running affected SMA1000 models are exposed, especially if appliances are internet-facing. The risk is higher where administrators cannot quickly verify patch status or determine whether indicators of compromise are present.