On September 1, 2026, SonicWall disclosed two vulnerabilities in its SMA 1000 appliances that the vendor says are already being actively exploited. Chained together, they yield unauthenticated remote code execution – full access to the VPN gateway without valid credentials.
The two flaws in detail
CVE-2026-83548 is a pre-auth Server-Side Request Forgery (SSRF) in the “Work Place” interface, rated the maximum CVSS 10.0. It lets unauthenticated attackers reach sensitive functionality. CVE-2026-83549 (CVSS 7.8) is an OS command injection in the Appliance Management Console (AMC) that an attacker authenticated as administrator can abuse to run arbitrary system commands. Combined, they bypass authentication and enable unauthenticated RCE. As VPN and access gateways, SMA 1000 appliances are typically exposed directly to the internet, which makes a compromise especially serious: whoever controls the appliance sits at the perimeter of the corporate network.
Affected and patched versions
- Affected: SMA 1000 models 6210, 7210 and 8200v on firmware 12.4.3-03453 or 12.5.0-02835 and earlier
- Patched: Hotfix 12.4.3-03526 or 12.5.0-02952 and higher
- Not affected: the SMA 100 series and SSL-VPN on SonicWall firewalls
- To-do: Update to the hotfix immediately, keep the AMC off the public internet, review logs for compromise
Active exploitation confirmed
SonicWall’s PSIRT states it investigated a case indicating active exploitation and urges customers to update at once. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 3, 2026. Note: this incident is not the same as the earlier July case (CVE-2026-15409/15410). Because SonicWall has not published indicators of compromise (IoCs), operators should assume possible prior compromise after patching and reset credentials and active sessions.
Sources: SonicWall PSIRT (SNWLID-2026-0016) · BleepingComputer · The Hacker News · SecurityWeek



















