Security researchers are warning of a sophisticated cyberattack targeting SonicWall SMA1000 appliances by chaining two critical vulnerabilities. This attack allows threat actors to achieve remote code execution on compromised systems, according to Channeldive.The exploitation involves a maximum-severity server-side request forgery flaw, CVE-2026-83548, in the Appliance Work Place interface, combined with a high-severity OS command injection vulnerability, CVE-2026-83549, in the Appliance Management Console. This combination grants attackers access to sensitive functions and the ability to execute unauthorized commands. SonicWall has confirmed these flaws are being actively exploited in the wild and has urged users to apply the latest hotfix.The Cybersecurity and Infrastructure Security Agency has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating mitigation for federal agencies. SonicWall SMA appliances are commonly used to provide secure remote access, making them attractive targets, especially as the Appliance Work Place interface is often exposed to the public internet. This incident follows a similar pattern of exploitation against SonicWall SMA1000 devices in July.Source: Channeldive