SonicWall warns that threat actors are actively exploiting two zero-day flaws in its SMA1000 appliances. The vulnerabilities, identified as CVE-2026-83549 and CVE-2026-83548, can be chained to achieve unauthenticated remote code execution. SecurityWeek and Bleeping Computer both report that the attacks target systems without requiring prior authentication.

Both outlets describe the same core technical scenario: the two issues are used together in an exploit chain rather than independently. SonicWall alerts customers that exploitation is occurring in the wild, meaning defenders should treat the vulnerabilities as urgent rather than hypothetical. The coverage also emphasizes that the Remote Code Execution impact can be reached by attackers by leveraging the chaining behavior.

While the articles focus on similar facts—affected product family, vulnerability identifiers, and the unauthenticated chaining leading to remote code execution—they differ mainly in framing and wording. Both sources present SonicWall’s notice as the primary basis for the reports, with no clear additional details about attacker groups, timelines, or specific affected environments beyond the existence of active exploitation.