Attackers are actively chaining two previously unknown vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 Series appliances to seize control of the devices, the vendor has confirmed.[1][3] The flaws, tracked as CVE-2026-83548 and CVE-2026-83549, are already being used in attacks against exposed gateways that provide remote access and VPN connectivity for midsize and large enterprises.[1][2][3] SonicWall describes the incident as active exploitation with no available workaround and is urging customers to apply emergency hotfixes immediately.[1][3]
The first bug, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA 1000 Appliance WorkPlace interface, caused by an unintended alternate access path that effectively turns the gateway into an unauthorized forward proxy.[1][2][4][5] With a maximum CVSS v3 score of 10.0, the flaw allows a remote, unauthenticated attacker to send crafted requests through the device to internal resources and “gain unauthorized access to sensitive functionality and perform unauthorized operations,” according to SonicWall’s advisory.[1][3][5] Security trackers describe the issue as a known exploited vulnerability that can let attackers pivot from the edge into internal services once the device is exposed to the internet.[4][5]
The second vulnerability, CVE-2026-83549, is a post-authentication operating system command injection flaw in the SMA 1000 Appliance Management Console (AMC), rated 7.8 under CVSS v3.[1][3] Under certain conditions, a logged-in administrator can be tricked or coerced into triggering malicious input, enabling an attacker to execute arbitrary commands on the underlying appliance.[1][3] When combined with the pre-auth SSRF bug, the two issues form a reliable exploit chain that can deliver full administrative control of affected gateways.[1][2][3]
According to SonicWall, only SMA 1000 models 6210, 7210 and 8200v—both physical and virtual—are affected, and only when running specific platform-hotfix firmware builds.[1][2][3][4] Impacted versions include SMA 1000 firmware 12.4.3-03453 and 12.5.0-02835 and earlier platform-hotfix releases, with fixes provided in hotfix builds 12.4.3-03526 and 12.5.0-02952.[1][2][4] SonicWall stresses that its SMA 100 Series appliances and SonicWall firewall SSL-VPN features are not impacted by these CVEs, a distinction that has caused confusion in past advisories.[2][3][6]
The company’s product notice states there is no mitigation short of patching: customers are instructed to upgrade to the latest hotfix available via their support portal, then contact SonicWall Technical Support for assistance reviewing their appliances for indicators of compromise.[1][4] If signs of compromise are found, SonicWall recommends fully reimaging or redeploying affected hardware or virtual appliances, changing all user and administrator passwords, and resetting time-based one-time password (TOTP) tokens to evict attackers and restore trust in the environment.[1][4]
The new zero-days extend a difficult run for the SMA 1000 line, which has faced multiple waves of critical vulnerabilities and active exploitation in the last two years, including prior pre-auth SSRF and post-auth command injection flaws disclosed in mid-2026.[9][14][15] Security advisories from national cybersecurity agencies and independent researchers have repeatedly warned that internet-facing VPN and remote access gateways are high-value targets, and that SonicWall’s SMA 1000 issues have been rapidly weaponized in previous campaigns.[8][10][14][15] With fresh exploitation now confirmed, organizations still running unpatched SMA 1000 appliances should treat them as at-risk edge infrastructure, assume potential compromise, and move quickly to patch, harden access, and increase monitoring around these devices.[1][3][4]
References
- SMA 1000 Series affected by Multiple Vulnerabilities …
- CVE-2026-83548 and CVE-2026-83549
- SonicWall SMA 1000 appliances under attack via zero-day …
- CVE-2026-83548 Exploited in the Wild — SMA1000 | Previdian
- CVE-2026-83548 – Vulnerability Details – OpenCVE
- Exploitation of Critical Vulnerability CVE-2025-23006 in SonicWall SMA1000 Series Appliances – NHS England Digital
- Multiple Vulnerabilities in SonicWall SMA1000 Series
- Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities
- Objet: Multiples vulnérabilités dans Sonicwall Secure Mobile Access
- SonicWall SMA1000 vulnerabilities in active exploitation
- SonicWall SMA Zero-Days: Edge Appliance Root Returns
