CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of two vulnerabilities affecting the SonicWall SMA1000. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.

SonicWall SMA1000 (Secure Mobile Access 1000 Series) is an enterprise-grade secure remote access gateway. It’s a VPN and Zero Trust access appliance — used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.

CVE-2026-83548: Pre-authentication Server-Side Request Forgery Vulnerability

The vulnerability has a critical severity rating with a CVSS score of 10. This SSRF vulnerability exists in the SMA1000 Appliance Work Place interface, originating from an unintended alternate access path. This pre-authentication vulnerability may allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVE-2026-83549: Post-authentication Remote Code Execution Vulnerability

The vulnerability has a high severity rating with a CVSS score of 7.8. The OS Command Injection vulnerability exists in the SMA1000 Appliance Management Console (AMC). Under specific conditions, the vulnerability may allow an authenticated remote administrator to execute arbitrary OS commands, resulting in remote code execution.

Affected Versions

Affected Product Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions.

12.5.0-02835 (platform-hotfix) and older versions.

Mitigation

Fixed Product Fixed Version(s)
SMA1000 Models – 6210, 7210, 8200v 12.4.3-03526 (platform-hotfix) and higher versions.

12.5.0-02952 (platform-hotfix) and higher versions.

For more information, please refer to the SonicWall Security Advisory (SNWLID-2026-0016).

Qualys Detection

Qualys customers can scan their devices with QID 388624 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016