SonicWall security advisory (AV26-872) – Update 1
CISA added exploited SonicWall SMA1000 flaws CVE-2026-83548 and CVE-2026-83549 to KEV; admins of affected hotfix versions should patch.
Canada's Cyber Centre (advisory AV26-872, Update 1) relays a SonicWall advisory for SMA1000 appliances (6210, 7210, 8200v), stating CVE-2026-83548 and CVE-2026-83549 are being exploited. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, 2026. Affected versions include platform-hotfix 12.4.3-03453 and 12.5.0-02835 and older; administrators should apply available updates.
- SonicWall confirmed CVE-2026-83548 and CVE-2026-83549 are being exploited against SMA1000 appliances.
- CISA added both flaws to KEV on September 2, 2026.
- Affected versions include platform-hotfix 12.4.3-03453 and 12.5.0-02835 and older; patch promptly.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-83548 +1 in the same advisory: …83549 | Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known. Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated. | 10.0 group max | 5% | KEV |
| moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate) |
Full article102 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-872
Date: September 2, 2026
As of September 1, 2026, SonicWall is affected by a vulnerability in the following product:
SMA1000 - 6210, 7210, 8200v
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited.
Update 1
On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Security Advisory
SonicWall Security Advisories
CISA KEV: CVE-2026-83548
CISA KEV: CVE-2026-83549
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-872