Summary
SonicWall has confirmed that attackers are actively exploiting two newly disclosed zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. The first flaw, CVE-2026-83548, is a maximum-severity pre-authentication server-side request forgery (SSRF) weakness in the appliance’s Work Place interface that lets an unauthenticated attacker reach sensitive internal functionality. The second, CVE-2026-83549, is an operating system command injection flaw in the Appliance Management Console (AMC) that an administrator-level attacker can use to run arbitrary commands on the device. SonicWall discovered the issues internally, has released hotfixes, and is urging every customer to patch without delay.
Vulnerability Details
Finding #1
SonicWall has issued security updates for two vulnerabilities in its SMA 1000 series VPN appliances that attackers have already been exploiting as zero-days. CVE-2026-83548 is classified as a server-side request forgery issue (CWE-918) in the Appliance Work Place interface, the user-facing portal exposed to the internet. Because it can be triggered before any authentication, a remote attacker can abuse the appliance to make requests on their behalf and reach functionality that should never be accessible from outside.
Finding #2
CVE-2026-83549 is an operating system command injection flaw (CWE-78) in the Appliance Management Console, the administrative back end of the device. Under specific conditions, an attacker operating with administrator privileges can inject and execute arbitrary OS commands, which translates directly into remote code execution on the underlying system. Considered together, the two flaws carry a high potential for chaining: pairing a pre-authentication weakness with a code-execution flaw could let attackers progress from an unauthenticated foothold toward full control of the appliance.
Finding #3
The flaws affect both physical and virtual SMA 1000 models, specifically the 6210, 7210, and 8200v, running firmware 12.4.3-03453 (platform-hotfix) and 12.5.0-02835 (platform-hotfix) or earlier. Importantly, the SMA 100 series and SonicWall’s firewall SSL-VPN offerings are not affected, which narrows the exposure to organizations specifically running SMA 1000 hardware or virtual appliances.
Finding #4
SonicWall’s Product Security Incident Response Team confirmed it investigated a case pointing to active exploitation of these vulnerabilities. Because attacks are already underway against internet-facing appliances, applying the available hotfix immediately is essential; every day an unpatched SMA 1000 stays online is a day it can be targeted with a flaw that is being exploited right now.
Vulnerability & CPE Reference
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-83548 | SonicWall SMA 1000 (6210, 7210, 8200v) 12.4.3-03453 and 12.5.0-02835 (platform-hotfix) and older | cpe:2.3:a:sonicwall:sma1000:*:*:*:*:*:*:*:* | CWE-918, CWE-441 |
CVE-2026-83549 | SonicWall SMA 1000 (6210, 7210, 8200v) 12.4.3-03453 and 12.5.0-02835 (platform-hotfix) and older | cpe:2.3:a:sonicwall:sma1000:*:*:*:*:*:*:*:* | CWE-78 |
Recommendations
Upgrade every SMA 1000 appliance to the fixed firmware, version 12.4.3-03526 (platform-hotfix) or 12.5.0-02952 (platform-hotfix), as soon as possible. With attacks already underway and a CVSS 10.0 flaw in play, patching should take priority over routine maintenance windows.
If you find evidence of compromise, re-image physical appliances or re-deploy virtual ones from a known-good state, then change all user and administrator passwords and reset every TOTP token.
Limit who can reach the SMA 1000 management interfaces by restricting administrative access to trusted networks and, where possible, placing the appliance behind additional access controls.
Maintain an accurate inventory of edge and remote-access devices, monitor vendor advisories closely, and build a process to test and deploy security hotfixes quickly.
MITRE ATT&CK TTPs
References & Patch Links
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
