| Product | Affected versions | Fixed versions |
|---|---|---|
| SMA1000 6210, 7210, 8200v | 12.4.3-03453 and older | 12.4.3-03526 |
| SMA1000 6210, 7210, 8200v | 12.5.0-02835 and older | 12.5.0-02952 |
SonicWall CVE-2026-83548 Leads to CISA Alert
SonicWall disclosed two actively exploited vulnerabilities in SMA1000 Series appliances: CVE-2026-83548, a pre-authentication server-side request forgery flaw, and CVE-2026-83549, a post-authentication OS command injection flaw.
SonicWall released fixed platform hotfixes on September 1, 2026. CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026, with a remediation due date of September 5, 2026 for federal agencies.
What Are CVE-2026-83548 and CVE-2026-83549?
CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. SonicWall describes it as an unintended forward-proxy or alternate access path that could allow an unauthenticated remote attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. SonicWall rates it Critical, with a CVSS score of 10.0.

Details of CVE-2026-83548 (SOCRadar Vulnerability Intelligence)
CVE-2026-83549 is a post-authentication OS command injection vulnerability in the Appliance Management Console (AMC). Under specific conditions, a remote authenticated administrator could execute arbitrary operating system commands, resulting in remote code execution. SonicWall rates it High, with a CVSS score of 7.8.

Details of CVE-2026-83549 (SOCRadar Vulnerability Intelligence)
The two issues have different prerequisites, but their combined risk is serious because SMA1000 appliances often protect remote access into enterprise environments.
Which SonicWall SMA1000 Versions Are Affected?
SonicWall says the vulnerabilities affect SMA1000 6210, 7210, and 8200v appliances, including all supported hypervisor deployments, on the affected platform hotfix levels.
Administrators should verify the full platform-hotfix level, not only the major firmware branch. SonicWall says these vulnerabilities are unrelated to other reported vulnerabilities in other SonicWall products.
How Could the Vulnerabilities Be Exploited?
At a high level, an attacker could target a network-reachable Appliance Work Place interface and abuse the SSRF condition in CVE-2026-83548 to reach sensitive functionality through an unintended access path.
The command injection flaw, CVE-2026-83549, affects AMC and normally requires administrator authentication. Public technical details do not fully document the complete exploitation sequence, so defenders should avoid assuming exact payloads, endpoints, or post-exploitation behavior beyond SonicWall’s advisory.
Successful exploitation could affect appliance operations, sensitive functionality, configuration integrity, and command execution in the appliance context.
Is There Active Exploitation?
Yes. SonicWall states that the vulnerabilities have been confirmed as actively exploited in the wild. The advisory does not provide a named threat actor, victim count, detailed exploit chain, or public indicators of compromise.
Both SonicWall SMA1000 flaws carry the same CISA due date: September 5, 2026. A three-day federal remediation window is effectively an immediate action requirement for any internet-facing SMA1000 deployment.
What Should Defenders Do Now?
Upgrade affected SMA1000 appliances to the fixed platform hotfix version for the deployed branch:
- 12.4.3-03526
- 12.5.0-02952
SonicWall says affected organizations should also contact SonicWall Technical Support for help reviewing systems for indicators of compromise. If IoCs are detected, SonicWall recommends re-imaging hardware appliances or redeploying virtual appliances, changing all user and administrator passwords, and resetting Time-based One-Time Password (TOTP) tokens.
If immediate patching is not possible, restrict access to remote access and management interfaces to trusted sources. This is exposure reduction, not a replacement for applying the hotfix.
How Can SOCRadar Help?
With SOCRadar’s Cyber Threat Intelligence, you can stay updated on CVE-2026-83548 and CVE-2026-83549 with real time tracking of KEV status, active exploitation developments, and vendor advisories.
Additionally, SOCRadar’s Attack Surface Management (ASM) continuously scans your digital footprint to detect internet-facing SonicWall SMA1000 appliances, exposed services, and vulnerable components – empowering your organization to quickly validate hotfixes and prioritize high risk systems for compromise assessment.

SOCRadar’s ASM, Company Vulnerabilities
How Can Teams Hunt for Possible Compromise?
SonicWall’s public notice does not include detailed IoCs, so defenders should review SMA1000 logs and surrounding telemetry for suspicious behavior, including:
- unusual Appliance Work Place requests,
- unexpected outbound or proxy-like requests from the appliance,
- abnormal AMC or administrator activity,
- new or modified administrative accounts,
- password resets or TOTP changes,
- unexplained configuration changes,
- unexpected process execution or system artifacts.
Version checks can identify vulnerable systems, but they cannot prove whether an appliance was previously compromised. Internet-facing SMA1000 appliances should be reviewed even after patching.

