ZoomEye finds 55,812 SonicWall SSL-VPN assets exposed over HTTP
ZoomEye identified 92,478 SonicWall SSL-VPN assets, with 55,812 also exposing an HTTP service. The finding comes as SonicWall patches two SMA1000 flaws: CVE-2026-83548, a pre-auth SSRF in the Work Place portal, and CVE-2026-83549, an OS command injection in the admin console, both already exploited.
- ZoomEye: 92,478 SonicWall SSL-VPN assets, 55,812 with HTTP service
- CVE-2026-83548 is a pre-auth SSRF in the Work Place portal
- CVE-2026-83549 is OS command injection in the admin console, scored 7.8
- Both flaws are in CISA's KEV catalog, remediation due 5 September 2026
Read next
Security