Skip to content
CVEvulnerabilityVulnerability ResearchCritical Infrastructure

SonicWall SMA1000 CVE-2026-83548 and CVE-2026-83549: CVSS 10.0, actively exploited

3 min read
Share

What was disclosed

On September 1, 2026, SonicWall disclosed two vulnerabilities in SMA1000 Appliances under advisory SNWLID-2026-0016. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) in the SMA1000 Work Place interface with a CVSS v3.1 base score of 10.0. It allows an unauthenticated remote attacker to access sensitive internal functionality through an unintended alternate access path. CVE-2026-83549 is an OS command injection flaw in the same product line. SonicWall confirmed both are being actively exploited in the wild at the time of disclosure.

How the chain works

Rapid7's Emergent Threat Response team confirmed that the two CVEs are being used in combination. CVE-2026-83548 provides the initial unauthenticated foothold by abusing the SSRF to probe and reach internal services. CVE-2026-83549 then delivers the OS command injection payload. Together they achieve unauthenticated remote code execution on the appliance. No public proof-of-concept exploit or indicators of compromise were available at the time of Rapid7's analysis, and no threat actor has been attributed, but Rapid7 assessed the activity as likely opportunistic given the large install base of SMA1000 in enterprise remote access deployments.

Who is affected

SonicWall SMA1000 series appliances running firmware earlier than 12.4.3-02741 are affected. The SMA1000 line is commonly deployed as a remote access gateway in enterprise environments. Organizations using SMA1000 for VPN or zero-trust network access are directly exposed.

What to do now

Patch to firmware 12.4.3-02741 or later immediately. Both CVEs are on the CISA Known Exploited Vulnerabilities catalog with an FCEB agency deadline of September 23, 2026. If immediate patching is not possible, restrict access to the Work Place interface to trusted source IPs only, and review logs for anomalous access patterns to internal services originating from the appliance. If you see unexpected internal service requests or unusual command execution, treat the appliance as potentially compromised and initiate incident response procedures.

Context: SonicWall devices as a recurring target

SonicWall network edge devices have appeared repeatedly in exploitation campaigns over the past several years, including incidents attributed to Chinese state-sponsored actors and ransomware operators. Remote access appliances are high-value targets because they sit on the perimeter with broad network visibility and are often trusted by internal systems. A CVSS 10.0 flaw with pre-authentication exploitation actively occurring in the wild places this firmly in the must-patch-today category.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help assessing your exposure or managing a patching sprint on network edge devices.

Related articles