SonicWall SMA1000 zero-days CVE-2026-83548 and CVE-2026-83549 actively exploited; added to CISA KEV with September 5, 2026 patch deadline
SonicWall disclosed and patched two actively exploited SMA1000 zero-days: critical (CVSS 10.0) pre-auth SSRF CVE-2026-83548 and high (CVSS 7.8) post-auth OS command injection CVE-2026-83549, which chain to unauthenticated RCE per Rapid7. CISA added both to…
SonicWall has disclosed and patched two zero-day vulnerabilities in its SMA1000 secure access appliances (models 6210, 7210, 8200v) that are being actively exploited, confirmed by the vendor and relayed by Canada's Cyber Centre in advisory AV26-872 Update 1. CVE-2026-83548 is a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface; CVE-2026-83549 is a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. Rapid7 assessed that chaining the two flaws yields unauthenticated remote code execution, a framing also reported by Dark Reading, though Qualys individually describes CVE-2026-83549 as post-authentication. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a September 5, 2026 remediation due date. Affected installations run platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older; fixes ship in 12.4.3-03526 and 12.5.0-02952. The vendor published no IOCs or victim counts and urged customers to hunt for compromise, reimage or redeploy appliances, and reset all passwords and tokens. The product line has faced repeated exploitation: these are the fifth and sixth SMA1000 flaws added to KEV since mid-December 2025, INC and Akira ransomware groups have historically targeted SonicWall devices, and Dark Reading notes the exploitation follows earlier summer attacks abusing two other SonicWall edge zero-days. Qualys customers can detect vulnerable assets via QID 388624.
- SonicWall confirmed CVE-2026-83548 and CVE-2026-83549 are being exploited against SMA1000 appliances; Cyber Centre advisory AV26-872 Update 1 relays the vendor advisory (2026-09-02).
- CVE-2026-83548: critical, CVSS 10.0, pre-authentication SSRF in the SMA1000 Appliance Work Place interface (Qualys).
- CVE-2026-83549: high, CVSS 7.8, post-authentication OS command injection leading to RCE in the Appliance Management Console (Qualys); Rapid7, cited by CyberScoop, assessed that chaining the two flaws yields unauthenticated RCE, a framing…
- CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 2, 2026, with a remediation due date of September 5, 2026 (Cyber Centre, Qualys, CyberScoop).
- Affected products: SMA1000 models 6210, 7210, and 8200v running platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older (Cyber Centre, Qualys).
- Fixes are available in platform-hotfix 12.4.3-03526 and 12.5.0-02952 (Qualys).
- No IOCs or victim counts have been published; the vendor advises hunting for compromise, reimaging or redeploying appliances, and resetting all passwords and tokens (CyberScoop).
- These are the fifth and sixth SonicWall SMA1000 flaws added to KEV since mid-December 2025; INC and Akira ransomware groups have historically targeted SonicWall devices (CyberScoop), and the exploitation follows earlier summer attacks on…
Coverage timelineoldest first · each row is one article
- · 13d agoSonicWall security advisory (AV26-872) – Update 1
Canadian Centre for Cyber Security· 80
CISA added exploited SonicWall SMA1000 flaws CVE-2026-83548 and CVE-2026-83549 to KEV; admins of affected hotfix versions should patch.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-83548 +1 in the same advisory: …83549 | Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known. Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated. | 10.0 group max | 5% | KEV |
| moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate) |