CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation
The second SonicWall SMA1000 zero-day chain in seven weeks, and this time the vendor's own advisory names the exploitation itself
Defender actions
- Apply SonicWall's hotfix 12.4.3-03526 or 12.5.0-02952 to every SMA1000 6210/7210/8200v appliance now; if immediate patching is not possible, remove the appliance from internet exposure entirely rather than relying on network-layer filtering alone, since the SSRF reaches internal functionality through the appliance's own Work Place interface.
- Where indicators of compromise are found, follow SonicWall's own remediation position: re-image or re-deploy the appliance, rotate every user and administrator password, and reset TOTP seeds; SonicWall's guidance treats successful exploitation as credential- and MFA-seed-compromising, not just appliance-compromising.
Analysis
SonicWall's SMA1000 is a secure remote-access appliance family used by enterprises and government agencies to front VPN, SSL-VPN and application-proxy access for remote users. SonicWall's advisory SNWLID-2026-0016 (updated 2026-09-01) discloses two flaws it states it has investigated as actively exploited (SonicWall PSIRT). CVE-2026-83548 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the SMA1000 Appliance Work Place interface, arising from an unintended alternate access path (CWE-918 SSRF, CWE-441 Confused Deputy); a remote, unauthenticated attacker uses it to reach functionality normally gated behind authentication (SonicWall PSIRT). CVE-2026-83549 (CVSS 3.0 7.8) is a post-authentication OS command injection in the Appliance Management Console (AMC), letting an attacker who already holds administrative access execute arbitrary operating-system commands (SonicWall PSIRT). Chained, the SSRF supplies the unauthorized access the command injection then turns into code execution, SecurityWeek and BleepingComputer both report the flaws are being exploited together, with the appliance considered fully compromised once both stages complete (SecurityWeek, 2026-09-02). Affected: SMA1000 physical and virtual models 6210, 7210 and 8200v on any release before the fixed hotfixes below; the SMA 100 Series and SonicWall firewall SSL-VPN are explicitly not affected (SecurityWeek, 2026-09-02). Fixed in hotfix 12.4.3-03526 or 12.5.0-02952 (SecurityWeek, 2026-09-02). Shadowserver tracks more than 400 SMA1000 appliances exposed to the internet, some of which may already be patched (BleepingComputer, 2026-09-02). CISA added both CVEs to its Known Exploited Vulnerabilities catalog on 2026-09-02 (CISA Known Exploited Vulnerabilities catalog, 2026-09-02).
This is the second SMA1000 zero-day chain disclosed in seven weeks: a 2026-07-14 entry covers CVE-2026-15409/CVE-2026-15410, an SSRF-to-command-injection pair on a different endpoint pair, exploited for weeks before disclosure and later abused by ransomware affiliates per CISA. No source ties this new chain to the same UTA0533 cluster or any other named actor; the recurrence is in the vulnerability class and product line, not in a confirmed shared operator.
SonicWall's own remediation guidance where indicators of compromise are found is unusually direct: re-image or re-deploy the appliance, change every user and administrator password, and reset TOTP tokens, treating successful exploitation as compromising stored credentials and MFA seeds, not just the appliance itself (SonicWall PSIRT). Triage: requests to the Work Place interface that trigger outbound connections to internal-only services, or AMC command-execution audit entries not tied to an interactive administrator session, are the observable signature the mechanism supports, a legitimate Work Place session has no reason to originate internal service-to-service traffic.
Cited evidence
SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.