ZeroHour
Story · 1 source · 1 articlefirst updated ()

Actively Exploited SonicWall SMA1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 Chain to Unauthenticated RCE; Hotfixes Released, CISA KEV Deadline September 5

criticalExploit / PoCexploited in the wildimportance 88CVE-2026-83548CVE-2026-83549
Merged summary · glm-5.3-flash · rewritten as coverage arrives

SonicWall disclosed on September 1, 2026 two zero-days in SMA1000 appliances (models 6210, 7210, 8200v): CVE-2026-83548, a critical pre-authentication SSRF (CVSS 10.0) in the Appliance Work Place interface, and CVE-2026-83549, a high (CVSS 7.8) authenticated…

SonicWall disclosed on September 1, 2026 that CVE-2026-83548, a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface, and CVE-2026-83549, a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console, can be chained for unauthenticated remote code execution on internet-exposed edge appliances. Both vulnerabilities were confirmed exploited in the wild, with exploitation occurring before public disclosure. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a required patch deadline of September 5, 2026. Affected products are SMA1000 models 6210, 7210 and 8200v running platform-hotfix 12.4.3-03526 or 12.5.0-02952's predecessors — version 12.4.3-03453 and 12.5.0-02835 or older. Remediation: upgrade to 12.4.3-03526 or 12.5.0-02952 platform-hotfixes, hunt for compromise, re-image or redeploy appliances, and reset all passwords and TOTP tokens. SonicWall provided no IOCs or victim counts. Detection is available via Qualys QID 388624 and Rapid7's September 3 release content. Context: this is the fifth and sixth SonicWall SMA 1000 flaw added to KEV since mid-December 2025, following earlier summer attacks abusing two other SonicWall edge zero-days; INC and Akira ransomware groups have historically targeted SonicWall devices.

  • CVE-2026-83548: critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface.
  • CVE-2026-83549: high (CVSS 7.8) authenticated/post-authentication OS command injection leading to RCE in the Appliance Management Console.
  • Chaining the two flaws yields unauthenticated remote code execution on internet-exposed SMA1000 edge appliances (per Rapid7).
  • SonicWall disclosed the vulnerabilities on September 1, 2026; both were exploited in the wild before public disclosure.
  • CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 2, 2026, with a patch deadline of September 5, 2026.
  • Affected products: SonicWall SMA1000 models 6210, 7210 and 8200v.
  • Affected versions: platform-hotfix 12.4.3-03453 and 12.5.0-02835 and older.
  • Fixed versions: platform-hotfix 12.4.3-03526 and 12.5.0-02952.

Coverage timeline

  1. · 13d ago
    Rapid7 Blog· 88
    Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

    SonicWall SMA1000 appliances face active exploitation of chained CVE-2026-83548 and CVE-2026-83549 enabling unauthenticated RCE; hotfixes released.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)