Active Exploitation of Vulnerabilities in SonicWall SMA1000 Series
4 September 2026
Attackers are exploiting vulnerabilities in SonicWall SMA1000 Series appliances to gain unauthorised access to sensitive functionalities and execute arbitrary operating system (OS) commands.
Background
SonicWall has released security updates to address multiple vulnerabilities (CVE-2026-83548, CVE-2026-83549) affecting SonicWall SMA1000 Series appliances. The vulnerabilities have Common Vulnerability Scoring System (CVSS) scores of: CVE-2026-83548 at 10.0 and CVE-2026-83549 at 7.8 out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-83548: Due to a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface arising from an unintended alternate access path, a remote unauthenticated attacker could gain unauthorised access to sensitive functionalities and perform unauthorised operations.
CVE-2026-83549: Successful exploitation of this post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC) could allow a remote authenticated attacker to execute arbitrary OS commands with administrator privileges, resulting in remote code execution.
Known Exploitation
These vulnerabilities are reportedly being actively exploited.
Affected Products
These vulnerabilities affect SMA1000 models 6210, 7210 and 8200v running:
12.4.3-03453 (platform-hotfix) and earlier
12.5.0-02835 (platform-hotfix) and earlier
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
Organisations with affected deployments of SMA1000 appliances are further advised to contact SonicWall Technical Support for assistance with checking for indicators of compromise (IoCs).
References
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-83548 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-83549 (opens in new tab)
