---
schema: 1
kind: vulnerability
title: "CVE-2026-83548 / CVE-2026-83549 — SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console — both under active exploitation"
headline: "The second SonicWall SMA1000 zero-day chain in seven weeks, and this time the vendor's own advisory names the exploitation itself"
summary: >
  SonicWall confirms active exploitation of two SMA1000 secure-remote-access flaws (SNWLID-2026-0016): CVE-2026-83548
  (CVSS 3.0 10.0), a pre-authentication SSRF in the Work Place interface via an unintended alternate access path, and
  CVE-2026-83549 (CVSS 3.0 7.8), a post-authentication OS command injection in the Appliance Management Console.
  Shadowserver tracks over 400 internet-exposed SMA1000 appliances. Fixed in hotfix 12.4.3-03526 / 12.5.0-02952;
  no fix exists short of upgrading, and this is the second SMA1000 zero-day chain reported in seven weeks.
discovered_at: "2026-09-03T05:09:30Z"
updated_at: null
event_date: "2026-09-01"
run_id: 2026-09-03T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, actively-exploited, zero-day, pre-auth, rce, cisa-kev, patch-available, auth-bypass]
regions: [global, europe]
sectors: [public-sector, finance, energy, healthcare, telco]
entities: []
techniques: [T1190, T1059]
affected_products: ["SonicWall SMA1000"]
cves:
  - id: CVE-2026-83548
    cvss: "10.0 (CVSS3.0)"
    epss: "0.0027"
    type: ssrf
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "SMA1000 6210, 7210, 8200v — all releases prior to the fixed hotfixes below"
    fixed: "Hotfix 12.4.3-03526 / 12.5.0-02952"
  - id: CVE-2026-83549
    cvss: "7.8 (CVSS3.0)"
    epss: "0.0092"
    type: rce
    vector: zero-click
    auth: admin-required
    status: [exploited, cisa-kev, patch-available]
    affected: "SMA1000 6210, 7210, 8200v — all releases prior to the fixed hotfixes below"
    fixed: "Hotfix 12.4.3-03526 / 12.5.0-02952"
sources:
  - url: "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016"
    publisher: "SonicWall PSIRT (advisory SNWLID-2026-0016)"
    date: "2026-09-01"
    role: primary
  - url: "https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/"
    publisher: "SecurityWeek"
    date: "2026-09-02"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/"
    publisher: "BleepingComputer"
    date: "2026-09-02"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA (Known Exploited Vulnerabilities catalog)"
    date: "2026-09-02"
    role: corroborating
closed_sources: []
evidence:
  - quote: "SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability."
    publisher: "SonicWall PSIRT (advisory SNWLID-2026-0016)"
  - quote: "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations."
    publisher: "SonicWall PSIRT (advisory SNWLID-2026-0016)"
  - quote: "Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain."
    publisher: "BleepingComputer"
verification: multi-source
sourcing_note: >
  SonicWall's own advisory confirms the two flaws, their CVSS scores and active exploitation, but does not itself
  state the affected hotfix versions or model names in its short-form advisory text as rendered; that detail is
  cited to SecurityWeek and BleepingComputer, both independently reporting the same figures.
confidence: high
references:
  - 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 1
watchlist_hit: false
actions:
  - "Apply SonicWall's hotfix 12.4.3-03526 or 12.5.0-02952 to every SMA1000 6210/7210/8200v appliance now; if immediate patching is not possible, remove the appliance from internet exposure entirely rather than relying on network-layer filtering alone, since the SSRF reaches internal functionality through the appliance's own Work Place interface."
  - "Where indicators of compromise are found, follow SonicWall's own remediation position: re-image or re-deploy the appliance, rotate every user and administrator password, and reset TOTP seeds — SonicWall's guidance treats successful exploitation as credential- and MFA-seed-compromising, not just appliance-compromising."
updates:
  - at: "2026-09-06T13:50:00Z"
    run_id: 2026-09-06T1308Z-audit
    type: correction
    internal: true
    summary: >
      Both EPSS values were ENISA EUVD's percentage rendering carried into a field that holds the
      FIRST.org probability, and each also carried a provenance suffix inside the numeric value.
      EUVD publishes EPSS multiplied by one hundred, so 0.27 and 0.92 are probabilities of 0.0027
      and 0.0092. Converted, with the provenance moved out of the value. No reader-facing statement
      changes.
    fields: [cves]
migrated_from: null
---

SonicWall's SMA1000 is a secure remote-access appliance family used by enterprises and government agencies to
front VPN, SSL-VPN and application-proxy access for remote users. SonicWall's advisory SNWLID-2026-0016 (updated
2026-09-01) discloses two flaws it states it has investigated as actively exploited
([SonicWall PSIRT](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016)). CVE-2026-83548 (CVSS 3.0 10.0)
is a pre-authentication server-side request forgery in the SMA1000 Appliance Work Place interface, arising from an
unintended alternate access path (CWE-918 SSRF, CWE-441 Confused Deputy); a remote, unauthenticated attacker uses it
to reach functionality normally gated behind authentication
([SonicWall PSIRT](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016)). CVE-2026-83549 (CVSS 3.0 7.8)
is a post-authentication OS command injection in the Appliance Management Console (AMC), letting an attacker who
already holds administrative access execute arbitrary operating-system commands
([SonicWall PSIRT](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016)). Chained, the SSRF supplies the
unauthorized access the command injection then turns into code execution — SecurityWeek and BleepingComputer both
report the flaws are being exploited together, with the appliance considered fully compromised once both stages
complete ([SecurityWeek, 2026-09-02](https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/)).
Affected: SMA1000 physical and virtual models 6210, 7210 and 8200v on any release before the fixed hotfixes below;
the SMA 100 Series and SonicWall firewall SSL-VPN are explicitly not affected
([SecurityWeek, 2026-09-02](https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/)).
Fixed in hotfix 12.4.3-03526 or 12.5.0-02952
([SecurityWeek, 2026-09-02](https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/)).
Shadowserver tracks more than 400 SMA1000 appliances exposed to the internet, some of which may already be patched
([BleepingComputer, 2026-09-02](https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/)).
CISA added both CVEs to its Known Exploited Vulnerabilities catalog on 2026-09-02
([CISA Known Exploited Vulnerabilities catalog, 2026-09-02](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)).

This is the second SMA1000 zero-day chain disclosed in seven weeks: a 2026-07-14 entry covers
CVE-2026-15409/CVE-2026-15410, an SSRF-to-command-injection pair on a different endpoint pair, exploited for weeks
before disclosure and later abused by ransomware affiliates per CISA. No source ties this new chain to the same
UTA0533 cluster or any other named actor — the recurrence is in the vulnerability class and product line, not in a
confirmed shared operator.

SonicWall's own remediation guidance where indicators of compromise are found is unusually direct: re-image or
re-deploy the appliance, change every user and administrator password, and reset TOTP tokens — treating successful
exploitation as compromising stored credentials and MFA seeds, not just the appliance itself
([SonicWall PSIRT](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016)). **Triage:** requests to the
Work Place interface that trigger outbound connections to internal-only services, or AMC command-execution audit
entries not tied to an interactive administrator session, are the observable signature the mechanism supports — a
legitimate Work Place session has no reason to originate internal service-to-service traffic. **Defender takeaway:**
any organisation running an internet-facing SMA1000 should patch to the current hotfix now and treat an unpatched,
exposed appliance as a probable target rather than a hypothetical one, given SonicWall's own confirmation of active
exploitation.
