SonicWall SMA1000 Hit by Second Zero-Day Chain in Seven Weeks, Same SSRF-to-Injection Pattern
SonicWall has disclosed a second zero-day chain affecting its SMA1000 series appliances within seven weeks. The vulnerabilities, detailed in SonicWall advisory SNWLID-2026-0016, consist of CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) in the Appliance Work Place interface, and CVE-2026-83549, a post-authentication OS command injection in the AMC component. Both flaws are actively exploited in the…