ZeroHour
Qualys ThreatPROTECTpublished ()ingested Diksha Ojha

CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)

criticalExploit / PoC exploited in the wildimportance 82CVE-2026-83548CVE-2026-83549
AI summary · glm-5.3-flash

CISA added two actively exploited SonicWall SMA1000 flaws to KEV: pre-auth SSRF CVE-2026-83548 (CVSS 10) and post-auth RCE CVE-2026-83549; patch by September 5.

CISA added CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. CVE-2026-83548 is a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface; CVE-2026-83549 is a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix and older are affected; fixes ship in 12.4.3-03526 and 12.5.0-02952. Qualys customers can detect vulnerable assets via QID 388624.

  • CISA added both SonicWall SMA1000 flaws to KEV; deadline September 5, 2026
  • CVE-2026-83548: critical CVSS 10.0 pre-auth SSRF in Appliance Work Place interface
  • CVE-2026-83549: high CVSS 7.8 authenticated OS command injection RCE in AMC
  • Affects models 6210/7210/8200v; fixed in 12.4.3-03526 and 12.5.0-02952 hotfixes
  • Qualys detects vulnerable assets with QID 388624

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)
Full article284 words · extracted from threatprotect.qualys.com · click to collapse

Skip to content

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of two vulnerabilities affecting the SonicWall SMA1000. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.

SonicWall SMA1000 (Secure Mobile Access 1000 Series) is an enterprise-grade secure remote access gateway. It’s a VPN and Zero Trust access appliance — used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.

CVE-2026-83548: Pre-authentication Server-Side Request Forgery Vulnerability

The vulnerability has a critical severity rating with a CVSS score of 10. This SSRF vulnerability exists in the SMA1000 Appliance Work Place interface, originating from an unintended alternate access path. This pre-authentication vulnerability may allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVE-2026-83549: Post-authentication Remote Code Execution Vulnerability

The vulnerability has a high severity rating with a CVSS score of 7.8. The OS Command Injection vulnerability exists in the SMA1000 Appliance Management Console (AMC). Under specific conditions, the vulnerability may allow an authenticated remote administrator to execute arbitrary OS commands, resulting in remote code execution.

Affected Versions

Affected Product Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions.

12.5.0-02835 (platform-hotfix) and older versions.

Mitigation

Fixed Product Fixed Version(s)
SMA1000 Models – 6210, 7210, 8200v 12.4.3-03526 (platform-hotfix) and higher versions.

12.5.0-02952 (platform-hotfix) and higher versions.

For more information, please refer to the SonicWall Security Advisory (SNWLID-2026-0016).

Qualys Detection

Qualys customers can scan their devices with QID 388624 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

Text extracted automatically; images, tables and formatting may be missing. Original: https://threatprotect.qualys.com/2026/09/03/cisa-warns-of-sonicwall-sma1000-vulnerabilities-active-exploitation-cve-2026-83548-cve-2026-83549/