Published on September 2, 2026

[CVE-2026-83548, CVE-2026-83549] SonicWall SMA1000 Vulnerabilities Allow Unauthorized Access and Remote Code Execution


Severity

Critical

Detail

SonicWall has disclosed two security vulnerabilities affecting SMA1000 Series secure mobile access appliances under advisory SNWLID-2026-0016. SonicWall confirmed that its Product Security Incident Response Team investigated a case indicating that both vulnerabilities are being actively exploited in the wild.

The most severe vulnerability, CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SMA1000 Appliance Workplace interface. The flaw results from an unintended alternate access path that can function as a forward proxy. A remote unauthenticated attacker could exploit this vulnerability to access sensitive internal functionality and perform unauthorized operations on affected appliances.

The second vulnerability, CVE-2026-83549 is a post-authentication Remote Code Execution (RCE) vulnerability in the SMA1000 Appliance Management Console. The flaw is caused by improper neutralization of special characters in operating system commands. An authenticated attacker with administrator privileges could exploit the vulnerability to execute arbitrary commands on the underlying operating system.

Successful exploitation of these vulnerabilities could lead to unauthorized access, arbitrary command execution, credential theft, lateral movement, and compromise of affected environments. SonicWall noted that there are no workarounds available and strongly recommends immediate installation of the provided hotfixes.

CVE IDSummaryCVSS Score
CVE-2026-83548A pre-authentication SSRF vulnerability in the SonicWall SMA1000 Appliance Workplace interface could allow a remote unauthenticated attacker to access sensitive internal functionality and perform unauthorized operations.10.0 (Critical)
CVE-2026-83549A post-authentication command injection vulnerability in the SonicWall SMA1000 Appliance Management Console could allow an authenticated administrator to execute arbitrary operating system commands.7.8 (High)

Affected Products

The vulnerabilities affect the following SonicWall SMA1000 Series appliances:

  • SMA1000 6210, 7210, and 8200v running version 12.4.3-03453 and earlier.
  • SMA1000 6210, 7210, and 8200v running version 12.5.0-02835 and earlier.

SonicWall confirmed that SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected.

Recommendation

Organizations should implement the following measures to reduce the risk of exploitation:

  • Upgrade SMA1000 appliances to version 12.4.3-03526 or later or 12.5.0-02952 or later, depending on the deployed software branch.
  • Identify and prioritize all internet-facing SMA1000 appliances for immediate patching.
  • Contact SonicWall Technical Support for assistance in assessing potentially compromised systems.
  • Re-image affected physical appliances or redeploy affected virtual appliances if evidence of compromise is identified.
  • Change all user and administrator passwords after remediation activities.

Source

https://cybersecuritynews.com/sonicwall-remote-code-execution-vulnerabilities/

https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW