Two chained zero-days yield unauthenticated RCE on SonicWall SMA 1000 appliances
On September 1, 2026, SonicWall disclosed two flaws in the SMA 1000 line — a pre-authentication SSRF (CVE-2026-83548, CVSS 10) and an OS command injection (CVE-2026-83549) — already chained in the wild to reach remote code execution without credentials. Apply the hotfix now, and if compromise is confirmed, re-image the appliance instead of patching over the intrusion.