Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Zero-Days Exploited in the Wild

Critical CVE-2026-83548, CVE-2026-83549 — Two SonicWall SMA1000 flaws, a pre-auth SSRF and an admin command injection, are being chained by attackers for remote code execution. Affected versions, the hotfix builds, and what to check if you run one.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If your business uses a SonicWall SMA1000 for remote access, attackers are already exploiting two bugs in it: a pre-authentication SSRF in the Work Place portal and a command injection in the management console. Chained, they give remote code execution. Install 12.4.3-03526 or 12.5.0-02952 and assume an unpatched internet-facing box was compromised.

CVEsCVE-2026-83548 (SSRF) · CVE-2026-83549 (OS command injection)
ProductSonicWall SMA1000 series (e.g. 6210, 7210, 8200v)
Severity83548: Critical, no login required · 83549: High, needs admin access
Affected12.4.3-03453 platform-hotfix and older; 12.5.0-02835 platform-hotfix and older
Fixed in12.4.3-03526 · 12.5.0-02952
Exploited?Yes, zero-days. Added to CISA KEV 2026-09-02 with a 3-day federal deadline
AdvisorySNWLID-2026-0016

What’s going on

The SonicWall SMA1000 is a secure-remote-access appliance: it’s what staff log into from home to reach internal apps. That puts it on the internet by design, which is why attackers keep going after it.

  • CVE-2026-83548: the Work Place (user portal) interface has an unintended alternate access path. A remote, unauthenticated attacker can use it as a server-side request forgery to reach functionality that should require a login.
  • CVE-2026-83549: the Appliance Management Console (AMC) passes input to the operating system without sanitising it, so an attacker with admin access can run arbitrary OS commands.

Security researchers report the two being chained: the SSRF gets past authentication, the command injection turns that into code execution on the appliance. SonicWall confirmed both were exploited before a patch existed.

This keeps happening

This is the second pair of exploited SMA1000 bugs in two months. CISA added CVE-2026-15409 (SSRF) and CVE-2026-15410 (code injection) to its exploited list on 2026-07-14, both flagged as known ransomware use; they were fixed in builds after 12.4.3-03434 and 12.5.0-02800 (SNWLID-2026-0008), so the September hotfix covers them too. Edge VPN and remote-access appliances from every major vendor (SonicWall, Fortinet, Ivanti, Citrix) are now among the most common ways into small and mid-sized businesses. Patching within days, not weeks, is the only thing that keeps up.

Am I affected?

  1. Log in to the AMC and check the firmware version on the dashboard (or under System Configuration).
  2. If it’s 12.4.3-03453 or older on the 12.4 branch, or 12.5.0-02835 or older on 12.5, you’re vulnerable.
  3. Check whether the Work Place portal is reachable from the internet. It almost always is; that’s its job.

SMA100-series and SonicWall firewalls (TZ/NSa) are different products and aren’t covered by this advisory. Check SonicWall’s PSIRT for those separately.

How to patch

BranchVulnerableInstall
12.4.303453 platform-hotfix and older12.4.3-03526
12.5.002835 platform-hotfix and older12.5.0-02952

Download from MySonicWall and apply through the AMC. Take a configuration backup first. Schedule it now: CISA gave federal agencies three days, which tells you how urgent they consider it.

Until you patch

  • Restrict the management console (AMC) to an internal management network or a short allowlist of admin IPs. It should never be reachable from the internet.
  • If the business can survive a few hours without remote access, take the Work Place portal offline until the hotfix is in.
  • Make sure admin accounts use strong, unique passwords and MFA.

If it was exposed and unpatched: assume compromise

CISA flagged these for forensic triage, meaning it expects that patching alone may not remove an attacker who already got in. If your appliance was internet-facing on a vulnerable build:

  • Review the AMC for admin accounts, SSH keys, or configuration changes nobody on your team made.
  • Export and review the appliance logs for logins and management actions from unfamiliar IPs.
  • Reset passwords for every account that authenticates through the SMA, and rotate any credentials or certificates stored on it.
  • Check the internal systems the SMA can reach for new accounts, remote-access tools, or scheduled tasks.
  • Contact SonicWall support. They can help with appliance-level integrity checks.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories