SonicWall SMA1000 Vulnerabilities CVE-2026-83548 and CVE-2026-83549 Exploited in the Wild

· Original article ↗

Summary

SonicWall confirmed active exploitation of two vulnerabilities affecting SMA1000 appliances, including a critical unauthenticated SSRF flaw and a high-severity command injection flaw. Sophos researchers recommend identifying affected appliances and upgrading promptly.

Key points

  • SonicWall disclosed the vulnerabilities on September 1, 2026, and confirmed both are being exploited in the wild.
  • Affected SMA1000 models are 6210, 7210, and 8200v.
  • CVE-2026-83548 is a critical, unauthenticated SSRF vulnerability in the Appliance Work Place interface (CVSS 10.0).
  • CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (CVSS 7.8); under specific conditions, an authenticated administrator-level attacker could execute OS commands.
  • Sophos CTU recommends identifying vulnerable appliances and upgrading as soon as possible; the article does not specify patched versions.

Article Details

Vulnerability Types
  • Unauthenticated server-side request forgery in the SMA1000 Appliance Work Place interface
  • OS command injection in the Appliance Management Console under specific conditions
Severity
CVE-2026-83548: critical (CVSS 10.0); CVE-2026-83549: high (CVSS 7.8)
Exploitation Status
active
Exploit Availability
unknown
Patch Status
unknown

CVE

Vendors

Products

Related Articles