CTIPilot

SonicWall SMA1000, post-auth OS command injection in Appliance Management Console, actively exploited

cve · CVE-2026-83549

Coverage timeline
1
first 2026-09-03 → last 2026-09-03
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
3
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-03/cve-2026-83548-83549-sonicwall-sma1000-ssrf-cmd-injection · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-09-03/cve-2026-83548-83549-sonicwall-sma1000-ssrf-cmd-injection · ATT&CK page ↗

Story timeline

  1. 2026-09-03CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation
    trending-vulnerabilitiesThe second SonicWall SMA1000 zero-day chain in seven weeks, and this time the vendor's own advisory names the exploitation itself

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • bleepingcomputer.com1 (25%)
  • cisa.gov1 (25%)
  • psirt.global.sonicwall.com1 (25%)
  • securityweek.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SonicWall SMA1000, post-auth OS command injection in Appliance Management Console, actively exploited (1)

2026-09-03 · view entry permalink →

HIGHCVE-2026-83548 +1exploitedNATOB1

CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation

SonicWall's SMA1000 is a secure remote-access appliance family used by enterprises and government agencies to front VPN, SSL-VPN and application-proxy access for remote users. SonicWall's advisory SNWLID-2026-0016 (updated 2026-09-01) discloses two flaws it states it has investigated as actively exploited (SonicWall PSIRT). CVE-2026-83548 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the SMA1000 Appliance Work Place interface, arising from an unintended alternate access path (CWE-918 SSRF, CWE-441 Confused Deputy); a remote, unauthenticated attacker uses it to reach functionality normally gated behind authentication (SonicWall PSIRT). CVE-2026-83549 (CVSS 3.0 7.8) is a post-authentication OS command injection in the Appliance Management Console (AMC), letting an attacker who already holds administrative access execute arbitrary operating-system commands (SonicWall PSIRT). Chained, the SSRF supplies the unauthorized access the command injection then turns into code execution, SecurityWeek and BleepingComputer both report the flaws are being exploited together, with the appliance considered fully compromised once both stages complete (SecurityWeek, 2026-09-02). Affected: SMA1000 physical and virtual models 6210, 7210 and 8200v on any release before the fixed hotfixes below; the SMA 100 Series and SonicWall firewall SSL-VPN are explicitly not affected (SecurityWeek, 2026-09-02). Fixed in hotfix 12.4.3-03526 or 12.5.0-02952 (SecurityWeek, 2026-09-02). Shadowserver tracks more than 400 SMA1000 appliances exposed to the internet, some of which may already be patched (BleepingComputer, 2026-09-02). CISA added both CVEs to its Known Exploited Vulnerabilities catalog on 2026-09-02 (CISA Known Exploited Vulnerabilities catalog, 2026-09-02).

This is the second SMA1000 zero-day chain disclosed in seven weeks: a 2026-07-14 entry covers CVE-2026-15409/CVE-2026-15410, an SSRF-to-command-injection pair on a different endpoint pair, exploited for weeks before disclosure and later abused by ransomware affiliates per CISA. No source ties this new chain to the same UTA0533 cluster or any other named actor; the recurrence is in the vulnerability class and product line, not in a confirmed shared operator.

SonicWall's own remediation guidance where indicators of compromise are found is unusually direct: re-image or re-deploy the appliance, change every user and administrator password, and reset TOTP tokens, treating successful exploitation as compromising stored credentials and MFA seeds, not just the appliance itself (SonicWall PSIRT). Triage: requests to the Work Place interface that trigger outbound connections to internal-only services, or AMC command-execution audit entries not tied to an interactive administrator session, are the observable signature the mechanism supports, a legitimate Work Place session has no reason to originate internal service-to-service traffic.

SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

SonicWall PSIRT (advisory SNWLID-2026-0016) 2026-09-01

Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain.

BleepingComputer 2026-09-02

Builds on: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited

vulnerability03 Sep 05:09Zmulti-sourceOpen finding ↗