CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of two vulnerabilities affecting the SonicWall SMA1000. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.
SonicWall SMA1000 (Secure Mobile Access 1000 Series) is an enterprise-grade secure remote access gateway. It’s a VPN and Zero Trust access appliance — used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.
CVE-2026-83548: Pre-authentication Server-Side Request Forgery Vulnerability
The vulnerability has a critical severity rating with a CVSS score of 10. This SSRF vulnerability exists in the SMA1000 Appliance Work Place interface, originating from an unintended alternate access path. This pre-authentication vulnerability may allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVE-2026-83549: Post-authentication Remote Code Execution Vulnerability
The vulnerability has a high severity rating with a CVSS score of 7.8. The OS Command Injection vulnerability exists in the SMA1000 Appliance Management Console (AMC). Under specific conditions, the vulnerability may allow an authenticated remote administrator to execute arbitrary OS commands, resulting in remote code execution.
Affected Versions
| Affected Product | Affected Version(s) |
|---|---|
| SMA1000 Models – 6210, 7210, 8200v | 12.4.3-03453 (platform-hotfix) and older versions.
12.5.0-02835 (platform-hotfix) and older versions. |
Mitigation
| Fixed Product | Fixed Version(s) |
|---|---|
| SMA1000 Models – 6210, 7210, 8200v | 12.4.3-03526 (platform-hotfix) and higher versions.
12.5.0-02952 (platform-hotfix) and higher versions. |
For more information, please refer to the SonicWall Security Advisory (SNWLID-2026-0016).
Qualys Detection
Qualys customers can scan their devices with QID 388624 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

Comments are closed.