Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
SonicWall SMA1000 appliances face active exploitation of chained CVE-2026-83548 and CVE-2026-83549 enabling unauthenticated RCE; hotfixes released.
SonicWall disclosed on September 1, 2026 that CVE-2026-83548, a critical pre-authentication SSRF in the SMA1000 Appliance Work Place interface (CVSS 10.0), and CVE-2026-83549, an authenticated OS command injection in the Appliance Management Console, can be chained for unauthenticated remote code execution. Both vulnerabilities are confirmed exploited in the wild and were added to CISA's Known Exploited Vulnerabilities catalog. Affected SMA1000 models 6210, 7210 and 8200v on versions 12.4.3-03453 and 12.5.0-02835 platform-hotfix or earlier require upgrades to 12.4.3-03526 or 12.5.0-02952 platform-hotfixes.
- Chaining SSRF with command injection yields unauthenticated RCE on internet-exposed edge appliances
- Both CVEs added to CISA KEV; exploitation occurred before public disclosure
- SonicWall advises checking for compromise, re-imaging appliances and rotating all passwords and TOTP tokens
- Rapid7 shipping detection content in its September 3 release
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-83548 +1 in the same advisory: …83549 | Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known. Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated. | 10.0 group max | 5% | KEV |
| moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate) |
Full article499 words · extracted from rapid7.com · click to collapse

Overview
On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances.
CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path.
CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions. Although, by leveraging the SSRF vulnerability CVE-2026-83548 an attacker could potentially exploit CVE-2026-83549 to execute arbitrary OS commands without prior authentication.
SonicWall SMA1000 appliances are enterprise secure remote access gateways used to provide employees and other authorized users with access to internal applications and resources. Their role as network-edge systems makes successful exploitation particularly concerning, since affected Work Place interfaces may be exposed directly to the internet as part of normal deployment.
SonicWall has confirmed active exploitation of both vulnerabilities in the wild, and both CVE-2026-83548 and CVE-2026-83549 have been added to CISA's Known Exploited Vulnerabilities ( KEV ) catalog. No public proof-of-concept exploit, indicators of compromise (IOCs), or attribution for the current activity were identified in the research available at the time of publication.
The vulnerabilities affect SMA1000 Models - 6210, 7210, 8200v running the following versions:
Vulnerable Versions
Fixed Versions
12.4.3-03453 platform-hotfix and earlier
12.4.3-03526 (platform-hotfix) and higher versions
12.5.0-02835 platform-hotfix and earlier
12.5.0-02952 (platform-hotfix) and higher versions.
Mitigation guidance
Organizations operating affected SonicWall SMA1000 appliances should prioritize applying SonicWall’s updated platform hotfixes immediately. Because exploitation was occurring before public disclosure, organizations should not rely solely on patching to determine whether an appliance has already been compromised.
SonicWall recommends upgrading affected appliances to:
12.4.3-03526 platform-hotfix , for systems on the 12.4.3 branch
12.5.0-02952 platform-hotfix , for systems on the 12.5.0 branch
Affected Product/Component:
SonicWall SMA1000 Appliance Work Place and Appliance Management Console
Version 12.4.3-03453 platform-hotfix and earlier are affected.
Version 12.5.0-02835 platform-hotfix and earlier are affected.
SonicWall additionally recommends that customers contact SonicWall Technical Support for assistance reviewing appliances for indicators of compromise.
If evidence of compromise is identified, SonicWall recommends:
Re-imaging affected hardware appliances or re-deploying affected virtual appliances.
Changing all user and administrator passwords.
Resetting Time-based One-Time Password (TOTP) tokens.
Given the confirmed exploitation of these vulnerabilities, organizations should treat potentially exposed appliances running vulnerable software as a priority for investigation as well as remediation.
Please read the SonicWall security advisory for the latest vendor guidance.
Rapid7 customers
Exposure Command, InsightVM, and Nexpose
Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-83548 and CVE-2026-83549 in the SMA1000 Appliance series with vulnerability checks expected to be available in the September 3rd content release.
Updates
September 2, 2026: Initial publication.
September 3, 2026: CVE added to CISA KEV.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild