The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

SonicWall SMA1000 vulnerabilities CVE-2026-83549 and CVE-2026-83548, which allow remote code execution, are being exploited in attacks.

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks.