<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh" -->

---
title: SonicWall SMA1000 vulnerabilities CVE-2026-83548 and...
description: SonicWall disclosed two chained vulnerabilities in its SMA1000 series appliances that are already being actively exploited. CVE-2026-83548 is a pre-auth SSRF...
canonical: https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited | daily.dev
og:description: SonicWall disclosed two chained vulnerabilities in its SMA1000 series appliances that are already being actively exploited. CVE-2026-83548 is a pre-auth SSRF...
og:url: https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh
og:image: https://api.daily.dev/og/posts/6hvOQbRdH.png
og:image:alt: SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

SonicWall disclosed two chained vulnerabilities in its SMA1000 series appliances that are already being actively exploited. CVE-2026-83548 is a pre-auth SSRF (CVSS 10.0) in the Work Place interface, and CVE-2026-83549 is an OS command injection flaw (CVSS 7.8) in the Appliance Management Console; chained, they give unauthenticated attackers full remote code execution. Affected models are SMA 6210, 7210, and 8200v on firmware 12.4.3-03453 or 12.5.0-02835, with no workarounds available. Hotfixes 12.4.3-03526 and 12.5.0-02952 are out, but since exploitation predates disclosure, SonicWall recommends checking for compromise, re-imaging if compromised, and rotating passwords and TOTP tokens. The pattern echoes a prior SMA1000 exploitation chain tied to the INC ransomware group, and SonicWall has had 18-22 CVEs disclosed in the past year.

## Content

SonicWall has disclosed two zero-day vulnerabilities in its SMA1000 secure remote access appliances that are already being exploited in the wild. The flaws affect models 6210, 7210, and 8200v - not the SMA 100 series or firewall SSL-VPN products.

## What the vulnerabilities are

**CVE-2026-83548** is a pre-authentication server-side request forgery (SSRF) flaw in the WorkPlace user portal, rated CVSS 10.0. An unauthenticated attacker can exploit it to reach sensitive internal functionality without any credentials.

**CVE-2026-83549** is an OS command injection bug (CVSS 7.8) in the Appliance Management Console. It requires admin-level access, but Rapid7 noted the two flaws can be chained together - using the SSRF to impersonate an admin, then triggering the command injection - resulting in unauthenticated remote code execution.

Exploitation was happening before SonicWall made the vulnerabilities public, which matters for how organizations should respond.

## Affected versions and patches

Appliances running firmware 12.4.3-03453 or 12.5.0-02835 and older are vulnerable. SonicWall has released hotfixes:

- 12.4.3-03526
- 12.5.0-02952

There are no workarounds. Patching is the only fix.

## What to do if you're affected

SonicWall's guidance goes beyond just patching, and given that exploitation predates disclosure, that's reasonable:

1. Apply the hotfix immediately
2. Check for indicators of compromise
3. If compromise is found, re-image or redeploy the appliance rather than just patching it
4. Reset all passwords and TOTP tokens

As of the disclosure, Shadowserver counted over 400 SMA1000 appliances still exposed online.

## Context: this keeps happening

This isn't an isolated incident. SonicWall SMA1000 devices have been targeted repeatedly over the past year:

- A July zero-day chain was used to deploy custom malware
- CISA later confirmed ransomware operators exploited those same flaws
- A December zero-day enabled root privilege escalation

Security researchers have noted that the current SSRF-plus-command-injection chain closely mirrors the June/July exploit pattern that was weaponized by the INC ransomware operation. SonicWall has disclosed somewhere between 18 and 22 CVEs in the past year across its product line.

Third-party security operations centers are warning that further attacks are likely. If you're running SMA1000 appliances, treat this as urgent.

## Questions this post answers

### What are CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA1000 appliances?

CVE-2026-83548 is a pre-authentication SSRF vulnerability (CVSS 10.0) in the WorkPlace user portal that lets an unauthenticated attacker reach sensitive internal functionality. CVE-2026-83549 is an OS command injection flaw (CVSS 7.8) in the Appliance Management Console requiring admin access. Rapid7 found they can be chained: the SSRF impersonates an admin, then triggers command injection for unauthenticated remote code execution.

_daily.dev helps security teams track fast-moving vulnerability chains like this SonicWall SSRF and RCE pair._

### Which SonicWall SMA1000 firmware versions are vulnerable and what should I update to?

Firmware 12.4.3-03453, 12.5.0-02835, and older are vulnerable to the SSRF and command injection chain. SonicWall released hotfixes 12.4.3-03526 and 12.5.0-02952 to address both flaws. There are no workarounds, so patching is the only fix, and if compromise indicators are found, re-imaging or redeploying the appliance is recommended over patching alone.

_Teams managing SonicWall appliances rely on daily.dev to stay ahead of urgent patch requirements like this one._

### How many SonicWall SMA1000 appliances are still exposed to the SSRF vulnerability CVE-2026-83548?

Shadowserver counted over 400 SMA1000 appliances still exposed online as of the disclosure of CVE-2026-83548 and CVE-2026-83549. Exploitation of the flaws began before SonicWall made them public, and security researchers noted the exploit chain closely mirrors a prior SSRF-plus-command-injection pattern weaponized by the INC ransomware operation.

_Following exposure numbers and exploit trends for appliances like SonicWall SMA1000 is easier with daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited","url":"https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh"},"datePublished":"2026-09-03T02:30:57.526Z","dateModified":"2026-09-13T20:04:58.523Z","description":"SonicWall disclosed two chained vulnerabilities in its SMA1000 series appliances that are already being actively exploited. CVE-2026-83548 is a pre-auth SSRF...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fc21920cf1484401ad61b5a87ca35d17?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fc21920cf1484401ad61b5a87ca35d17?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ransomware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/sonicwall-sma1000-vulnerabilities-cve-2026-83548-and-cve-2026-83549-are-being-actively-exploited-6hvoqbrdh#faq","mainEntity":[{"@type":"Question","name":"What are CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA1000 appliances?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-83548 is a pre-authentication SSRF vulnerability (CVSS 10.0) in the WorkPlace user portal that lets an unauthenticated attacker reach sensitive internal functionality. CVE-2026-83549 is an OS command injection flaw (CVSS 7.8) in the Appliance Management Console requiring admin access. Rapid7 found they can be chained: the SSRF impersonates an admin, then triggers command injection for unauthenticated remote code execution. daily.dev helps security teams track fast-moving vulnerability chains like this SonicWall SSRF and RCE pair."}},{"@type":"Question","name":"Which SonicWall SMA1000 firmware versions are vulnerable and what should I update to?","acceptedAnswer":{"@type":"Answer","text":"Firmware 12.4.3-03453, 12.5.0-02835, and older are vulnerable to the SSRF and command injection chain. SonicWall released hotfixes 12.4.3-03526 and 12.5.0-02952 to address both flaws. There are no workarounds, so patching is the only fix, and if compromise indicators are found, re-imaging or redeploying the appliance is recommended over patching alone. Teams managing SonicWall appliances rely on daily.dev to stay ahead of urgent patch requirements like this one."}},{"@type":"Question","name":"How many SonicWall SMA1000 appliances are still exposed to the SSRF vulnerability CVE-2026-83548?","acceptedAnswer":{"@type":"Answer","text":"Shadowserver counted over 400 SMA1000 appliances still exposed online as of the disclosure of CVE-2026-83548 and CVE-2026-83549. Exploitation of the flaws began before SonicWall made them public, and security researchers noted the exploit chain closely mirrors a prior SSRF-plus-command-injection pattern weaponized by the INC ransomware operation. Following exposure numbers and exploit trends for appliances like SonicWall SMA1000 is easier with daily.dev."}}]}
```

