SonicWall Fixes Two Actively Exploited SMA1000 Flaws
SonicWall has released fixes for two vulnerabilities in SMA1000 devices and confirmed that they are being actively exploited in the wild. Affected organizations should update their systems and check for possible signs of compromise.

SonicWall SMA1000 fixes address two vulnerabilities that the manufacturer, according to a September 1, 2026 notice, lists as actively exploited in the wild. The issues affect Secure Mobile Access (SMA) 1000 devices, specifically the SMA 6210, 7210, and 8200v models.
Notice SNWLID-2026-0016 covers CVE-2026-83548 and CVE-2026-83549. SonicWall recommends that organizations deploy the available updates, check devices for indicators of compromise, and, if any are found, reinstall or redeploy the device along with taking additional security measures.
SonicWall SMA1000 fixes: Which flaws the manufacturer is addressing
CVE-2026-83548 is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. It has a maximum CVSS score of 10.0. SSRF could allow an attacker to force a vulnerable system to make requests from its own environment.
The second flaw, CVE-2026-83549, enables command execution in the AMC (Advanced Management Console) system after authentication. Its CVSS score is 7.8. SonicWall confirmed the exploitation of both flaws but did not disclose the attackers’ identities, the number of affected organizations, or technical details of the campaign.
Some secondary and official government sources warn that the two flaws could potentially be chained into unauthenticated remote code execution. However, SonicWall’s own notice describes CVE-2026-83548 separately as SSRF and CVE-2026-83549 as post-authentication command execution. The manufacturer therefore does not directly confirm chaining in the notice.
Affected versions and available updates
SMA 6210, SMA 7210, and SMA 8200v devices running firmware versions 12.4.3-03453 and earlier or 12.5.0-02835 and earlier are at risk. The fixed releases are:
- 12.4.3-03526 for the 12.4.3 branch,
- 12.5.0-02952 for the 12.5.0 branch.
Administrators should verify the exact version of their SMA1000 systems and move to the applicable fixed release. According to SonicWall, these vulnerabilities do not affect the SSL-VPN functionality in SonicWall firewalls or the SMA 100 Series product line.
An update alone may not be enough after a compromise
The manufacturer does not recommend limiting the response to deploying the fix. Organizations should check for indicators of compromise. If they find any, SonicWall recommends reinstalling or redeploying the device, changing passwords, and resetting the TOTP tokens used for multifactor authentication.
This procedure is particularly relevant for installations accessible from the internet. Remote-access devices operate at the edge of the internal network, and their compromise could give an attacker an access point into the corporate environment. The combination of a pre-authentication flaw and a flaw enabling command execution therefore poses a serious risk to unpatched SMA1000 systems.
What is not yet known
SonicWall has not yet stated whether a publicly available functional exploit exists or what persistence mechanisms the attackers may be using. It is also necessary to monitor whether the manufacturer publishes additional indicators of compromise or technical details, and whether national CERT teams and security researchers provide independent information about the scope of the exploitation.
For operators of affected systems, the immediate priority is to verify the version, deploy the applicable fix, and check for possible device compromise according to the manufacturer’s instructions.
Sources
- SonicWall Product Notice SNWLID-2026-0016 – Confirms active exploitation, affected models and versions, CVEs, severity ratings, fixed versions, and the recommended response when indicators of compromise are found.
- NHS England Digital – CC-4840 – Independently summarizes the affected platforms, fixes, and the risk of chaining the vulnerabilities into unauthenticated RCE.
- BleepingComputer – Corroborates the manufacturer’s recent warning and reported active attacks against SMA1000.
Verified and updated: 09/02/2026 17:02



