Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 actively exploited and chained for remote code execution

SonicWall has confirmed that attackers are actively exploiting its SMA1000 secure remote-access appliances, and it’s about as bad as these things get. They’re chaining two flaws: CVE-2026-83548, a server-side request forgery bug in the Appliance Work Place interface rated a maximum CVSS 10, with CVE-2026-83549, an OS command-injection flaw in the management console. Together they hand an unauthenticated attacker remote code execution on the box. SonicWall has issued a hotfix, and the US Cybersecurity and Infrastructure Security Agency has already added both to its Known Exploited Vulnerabilities catalogue with a mitigation deadline of today. (Cybersecurity Dive has the full write-up.)

Who’s affected: any business running a SonicWall SMA1000 appliance, particularly where the Appliance Work Place login is exposed to the public internet — which is the whole point of these devices. In the Australian SMB networks we manage, SSL-VPN boxes like this are among the most commonly forgotten pieces of kit: installed years ago so staff could work from home, then left running untouched because they never seemed to break. Plenty of Northern Beaches and Central West NSW businesses still lean on one for after-hours access. That “set and forget” habit is exactly what attackers are counting on, and it’s the second SMA1000 exploitation wave in two months.

What to do now: upgrade to SonicWall’s latest hotfix immediately. If you genuinely can’t patch today, restrict the Appliance Work Place interface so it isn’t open to the whole internet, review your logs for unusual admin activity, and treat any exposed appliance as potentially compromised — rotate credentials and check for persistence. Don’t wait for a quiet weekend.

Not sure whether you’ve even got one of these facing the internet? That’s a fair question, and it’s the kind of thing we check as part of managed cybersecurity and managed IT support. If you’d like us to confirm your remote-access setup is patched and locked down, get in touch.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →