- Product: SonicWall SMA1000
- Vulnerabilities: 2 flaws (CVE-2026-83548, CVE-2026-83549)
- Highest severity: 7.8 (High · CVSSv3)
- Worst impact: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS...
- Status: Exploited in the wild
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-83549 | 7.8 | CWE-78 | Exploited in the wild |
| CVE-2026-83548 | Awaiting analysis | CWE-441 | Exploited in the wild |
TL;DR
SonicWall published advisory SNWLID-2026-0016 on September 1, 2026. It confirms active exploitation of two SMA1000 flaws. The headline SonicWall SMA1000 vulnerability, CVE-2026-83548, is a pre-authentication SSRF rated a maximum 10.0 CVSS. A second bug, CVE-2026-83549, adds post-authentication remote code execution.
Why It Matters
SMA1000 appliances sit at the network edge as enterprise VPN gateways. Therefore, a pre-auth flaw exposes the front door to remote attackers. This SonicWall SMA1000 vulnerability needs no credentials and no user interaction.
A successful attacker reaches internal functionality that should stay hidden. From there, the second flaw can extend access into code execution. SonicWall confirms both are already under attack.
How the Attack Works
CVE-2026-83548 lives in the SMA1000 Work Place interface. The advisory describes it as an SSRF “due to an unintended alternate access path”. In effect, the appliance acts as an unintended forward proxy.
As a result, a remote unauthenticated attacker reaches sensitive functions. The advisory warns they could “perform unauthorized operations”. The second flaw, CVE-2026-83549, is an OS command injection in the Management Console. An authenticated admin could then run arbitrary commands. This report withholds exploit details.
Exploitation Status
SonicWall confirms active exploitation of this SonicWall SMA1000 vulnerability. Its PSIRT investigated a case that indicated real-world attacks. This mirrors a July 2026 SMA1000 campaign, when attackers chained a similar pre-auth SSRF with a code-execution flaw.
Affected Versions
The flaws affect SMA1000 models 6210, 7210, and 8200v. Vulnerable builds include 12.4.3-03453 and older, plus 12.5.0-02835 and older. The bugs do not affect SMA 100 Series devices or firewall SSL-VPN.
Patch and Mitigation Steps
No workaround exists, so patching is the only fix. Upgrade to 12.4.3-03526 or 12.5.0-02952, or later, from mysonicwall.com.
If You Find Indicators of Compromise
Contact SonicWall Support to review the appliance. Then re-image or re-deploy affected devices. Also change all user and admin passwords and reset TOTP tokens.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!