SonicWall Confirms Active Exploitation of Two SMA 1000 Vulnerabilities
SonicWall has confirmed the active exploitation of a critical SSRF flaw and an RCE vulnerability in SMA 1000 Series devices. Hotfixes are available for the affected versions.

SonicWall SMA 1000 vulnerabilities are being actively exploited, according to the vendor. On September 1, 2026, the company published notice SNWLID-2026-0016 covering two flaws in SMA 1000 Series devices and released corrective hotfixes. Organizations with affected systems should update the software and check for possible signs of compromise.
The flaws are designated CVE-2026-83548 and CVE-2026-83549. The first has a maximum CVSS score of 10.0 and is a pre-authentication SSRF vulnerability through an unintended forward proxy function. The second is a post-authentication vulnerability enabling remote code execution (RCE), with a CVSS score of 7.8.
SonicWall SMA 1000 vulnerabilities affect specific versions
The notice applies to the SMA 6210, SMA 7210, and virtual SMA 8200v models. Affected devices run software branches 12.4.3-03453 and 12.5.0-02835.
SonicWall prepared hotfixes for both branches:
- version 12.4.3-03526 fixes deployments on the 12.4.3 branch,
- version 12.5.0-02952 fixes deployments on the 12.5.0 branch.
The vendor explicitly confirmed that both flaws are being actively exploited. However, the published materials do not identify the attacker, the scope of affected organizations, or the specific techniques used in the attacks.
Why possible compromise must also be investigated
SMA devices provide remote access to corporate networks, so their compromise may also affect an organization’s internal environment. CVE-2026-83548 is a pre-authentication SSRF vulnerability with a CVSS score of 10.0.
The second flaw, CVE-2026-83549, requires authentication but may lead to remote code execution. Public materials do not technically describe whether or how attackers combine both vulnerabilities into a single attack chain. SonicWall did not explicitly confirm such a scenario in its notice.
The vendor recommends deploying the relevant hotfix without delay and checking the device for indicators of compromise. However, it did not publish specific indicators in the available notice.
If an organization finds signs of an attack, SonicWall recommends reinstalling or redeploying the device, changing passwords, and resetting TOTP tokens. The update itself removes the vulnerability, but it does not replace a response to a potential intrusion that has already occurred.
What is not known yet
It has not been confirmed whether CVE-2026-83548 or CVE-2026-83549 have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. The published information likewise does not mention forensic findings, malware, credential theft, or ransomware incidents directly linked to these flaws.
Further information may come from potential technical indicators of compromise from SonicWall, independent analyses of the attacks, or the vulnerabilities’ addition to the CISA KEV catalog. For administrators of affected SMA 1000 devices, however, a fix and the vendor’s procedure for suspected compromise are already available.
Sources
- SonicWall Product Notice SNWLID-2026-0016 – Confirms the CVEs, affected models and versions, active exploitation, corrective hotfixes, and the recommended procedure for possible compromise.
- SecurityWeek – Independently summarizes the SonicWall notice and states that public information does not yet include attack details or IoCs.
Verified and updated: 09/02/2026 07:37



