Critical CVE-2026-83548, CVE-2026-83549 — Two SonicWall SMA1000 flaws, a pre-auth SSRF and an admin command injection, are being chained by attackers for remote code execution. Affected versions, the hotfix builds, and what to check if you run one.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If your business uses a SonicWall SMA1000 for remote access, attackers are already exploiting two bugs in it: a pre-authentication SSRF in the Work Place portal and a command injection in the management console. Chained, they give remote code execution. Install 12.4.3-03526 or 12.5.0-02952 and assume an unpatched internet-facing box was compromised.
| CVEs | CVE-2026-83548 (SSRF) · CVE-2026-83549 (OS command injection) |
|---|---|
| Product | SonicWall SMA1000 series (e.g. 6210, 7210, 8200v) |
| Severity | 83548: Critical, no login required · 83549: High, needs admin access |
| Affected | 12.4.3-03453 platform-hotfix and older; 12.5.0-02835 platform-hotfix and older |
| Fixed in | 12.4.3-03526 · 12.5.0-02952 |
| Exploited? | Yes, zero-days. Added to CISA KEV 2026-09-02 with a 3-day federal deadline |
| Advisory | SNWLID-2026-0016 |
The SonicWall SMA1000 is a secure-remote-access appliance: it’s what staff log into from home to reach internal apps. That puts it on the internet by design, which is why attackers keep going after it.
Security researchers report the two being chained: the SSRF gets past authentication, the command injection turns that into code execution on the appliance. SonicWall confirmed both were exploited before a patch existed.
This is the second pair of exploited SMA1000 bugs in two months. CISA added CVE-2026-15409 (SSRF) and CVE-2026-15410 (code injection) to its exploited list on 2026-07-14, both flagged as known ransomware use; they were fixed in builds after 12.4.3-03434 and 12.5.0-02800 (SNWLID-2026-0008), so the September hotfix covers them too. Edge VPN and remote-access appliances from every major vendor (SonicWall, Fortinet, Ivanti, Citrix) are now among the most common ways into small and mid-sized businesses. Patching within days, not weeks, is the only thing that keeps up.
SMA100-series and SonicWall firewalls (TZ/NSa) are different products and aren’t covered by this advisory. Check SonicWall’s PSIRT for those separately.
| Branch | Vulnerable | Install |
|---|---|---|
| 12.4.3 | 03453 platform-hotfix and older | 12.4.3-03526 |
| 12.5.0 | 02835 platform-hotfix and older | 12.5.0-02952 |
Download from MySonicWall and apply through the AMC. Take a configuration backup first. Schedule it now: CISA gave federal agencies three days, which tells you how urgent they consider it.
CISA flagged these for forensic triage, meaning it expects that patching alone may not remove an attacker who already got in. If your appliance was internet-facing on a vulnerable build:
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.