SonicWall is urging SMA1000 customers to patch immediately after confirming active exploitation of two newly disclosed vulnerabilities, including a critical pre-authentication server-side request forgery flaw.
The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affect SMA1000 6210, 7210, and 8200v secure remote access appliances. SonicWall released fixed hotfixes on September 1 and recommends investigating affected systems for signs of compromise.
CVE-2026-83548 and CVE-2026-83549 can lead to RCE
According to SonicWall’s security advisory, CVE-2026-83548 is a pre-authentication SSRF vulnerability caused by an unintended forward-proxy function in the SMA1000 WorkPlace interface.
The flaw carries a maximum CVSS score of 10.0 and requires no authentication.
CVE-2026-83549 is a post-authentication remote code execution vulnerability in the Appliance Management Console. It has a CVSS score of 7.8 and requires administrator access when exploited on its own.
Rapid7 says the two flaws can be chained so CVE-2026-83548 provides unauthenticated access to functionality that can then be used to exploit CVE-2026-83549 and execute operating system commands without prior authentication.
SonicWall has confirmed active exploitation of both vulnerabilities but has not published attack details, attribution, or public indicators of compromise for the current activity.
Patch affected SMA1000 appliances immediately
The flaws affect SMA1000 6210, 7210, and 8200v appliances running the following vulnerable platform-hotfix versions:
-
12.4.3-03453 and earlier
-
12.5.0-02835 and earlier
Organizations should update to:
-
12.4.3-03526 or later
-
12.5.0-02952 or later
SonicWall also recommends contacting its technical support team to review affected appliances for indicators of compromise.
If compromise is detected, administrators should:
-
Re-image physical appliances or redeploy virtual appliances.
-
Change all user and administrator passwords.
-
Reset TOTP tokens.
Because SMA1000 appliances provide remote access to internal resources, organizations should prioritize exposed systems for both patching and investigation rather than treating the hotfix alone as sufficient remediation.
SMA1000 was also targeted in July
The disclosure follows another actively exploited SMA1000 vulnerability chain patched in July.
CVE-2026-15409 and CVE-2026-15410 affected the same appliance family and could be chained for remote code execution. The July fixes were 12.4.3-03453 and 12.5.0-02835, the same builds now listed as vulnerable to the newly disclosed flaws.
Volexity’s investigation found that threat actor UTA0533 had been exploiting the July vulnerabilities since at least June 22. Attackers gained root-level command execution and deployed malware including KNUCKLEBALL and the ORANGETAIL webshell.
eSecurity Planet previously covered the actively exploited July SMA1000 vulnerabilities, which were also added to CISA’s Known Exploited Vulnerabilities catalog.
Organizations that patched after the July incident still need the new hotfixes. The versions that fixed July’s vulnerabilities are now affected by CVE-2026-83548 and CVE-2026-83549.
Also read: China-linked hackers compromised Cisco IOS XR routers and used the infrastructure to create covert paths into other networks.





