CISA Adds Actively Exploited SonicWall SMA1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 to KEV; Patch Deadline September 5, 2026
CISA added two actively exploited SonicWall SMA1000 zero-days to the KEV catalog with a September 5, 2026 patch deadline: CVE-2026-83548 (critical, CVSS 10.0, pre-auth SSRF in the Appliance Work Place interface) and CVE-2026-83549 (high, CVSS 7.8, post-auth…
CISA has added two SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 5, 2026: CVE-2026-83548, a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface, and CVE-2026-83549, a high (CVSS 7.8) post-authentication OS command injection leading to remote code execution in the Appliance Management Console. Both flaws were being exploited in the wild as zero-days before patches were released. Rapid7, as cited by CyberScoop, reported that chaining the two flaws yields unauthenticated remote code execution; on their own, CVE-2026-83548 requires no authentication while CVE-2026-83549 requires authentication. Affected products are SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix builds and older; fixes ship in 12.4.3-03526 and 12.5.0-02952. Qualys customers can detect vulnerable assets via QID 388624. SonicWall provided no IOCs or victim counts and urged customers to hunt for compromise, reimage or redeploy appliances, and reset all passwords and tokens. These are the fifth and sixth SonicWall SMA 1000 flaws added to KEV since mid-December 2025; the product line has faced repeated exploitation, including by INC and Akira ransomware groups. Both sources agree on the CVEs, active exploitation, and the KEV addition; the exact CVSS scores (10.0 and 7.8) come from Qualys, with CyberScoop describing the SSRF as 'maximum severity' and the command injection as high severity.
- CISA added CVE-2026-83548 and CVE-2026-83549 (SonicWall SMA1000) to the Known Exploited Vulnerabilities Catalog, with a patch deadline of September 5, 2026; CyberScoop dates the KEV addition to Wednesday.
- CVE-2026-83548: pre-authentication SSRF in the SMA1000 Appliance Work Place interface, rated critical CVSS 10.0 by Qualys ('maximum severity' per CyberScoop).
- CVE-2026-83549: post-authentication OS command injection leading to RCE in the Appliance Management Console, rated high CVSS 7.8 by Qualys.
- Per Rapid7 (cited by CyberScoop), chaining the two flaws yields unauthenticated remote code execution.
- Both flaws were actively exploited in the wild as zero-days before patched releases (CyberScoop).
- Affected: SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix and older (Qualys).
- Fixed in platform-hotfix builds 12.4.3-03526 and 12.5.0-02952.
- No IOCs or victim counts have been published; SonicWall advises hunting for compromise, reimaging or redeploying appliances, and resetting all passwords and tokens.
Coverage timelineoldest first · each row is one article
- · 12d agoCISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)
Qualys ThreatPROTECT· 82
CISA added two actively exploited SonicWall SMA1000 flaws to KEV: pre-auth SSRF CVE-2026-83548 (CVSS 10) and post-auth RCE CVE-2026-83549; patch by September 5.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-83548 +1 in the same advisory: …83549 | Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known. Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated. | 10.0 group max | 5% | KEV |
| moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate) |