Security advisories

Critical Vulnerabilities in SonicWall SMA1000 Under Active Exploitation (CVE-2026-83548 and CVE-2026-83549)

September 2, 2026

3 MINS READ

THE THREAT

On September 1st, 2026, SonicWall published a security advisory disclosing two critical vulnerabilities, CVE-2026-83548 (CVSS: 10.0) and CVE-2026-83549 (CVSS: 7.8), affecting its SMA1000 Series Secure Mobile Access appliances.  Successful exploitation could provide attackers with a foothold on enterprise remote-access infrastructure, enabling unauthorized access to internal resources, execution of malicious commands, credential theft, persistence, and further lateral movement within the affected environment.

SonicWall has confirmed active exploitation of these vulnerabilities in the wild and has urged organizations to upgrade affected appliances immediately, review exposed systems for signs of compromise, and contact SonicWall technical support if compromise is suspected.

There are no workarounds available for either vulnerability, increasing the importance of immediate patching.

What we're doing about it

What you should do about it

Additional information

CVE-2026-83548 (CVSS 10.0) - A pre-authentication server-side request forgery (SSRF) vulnerability in the Appliance Work Place interface, allowing a remote, unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVE-2026-83549 (CVSS 7.8) - A post-authentication OS command injection vulnerability in the Appliance Management Console (AMC), allowing a remote, authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to Remote Code Execution (RCE).

At the time of writing, technical details on the vulnerabilities are limited, and there is no publicly available Proof-of-Concept (PoC) exploit code. SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected. However, given that SonicWall has confirmed active exploitation in the wild, organizations running affected SMA1000 appliances should prioritize patching without delay.

Impacted Product List
Product Affected Version(s) Fixed Version(s)
SMA1000 Models - 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions.

12.5.0-02835 (platform-hotfix) and older versions.
12.4.3-03526 (platform-hotfix) and higher versions.

12.5.0-02952 (platform-hotfix) and higher versions.

References:

[1] https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

[2] https://nvd.nist.gov/vuln/detail/cve-2026-83548

[3] https://nvd.nist.gov/vuln/detail/cve-2026-83549

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories