www.rapid7.com 9/2/2026, 8:17:18 PM · external

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CyberSIXT Evidence Panel

ON September 1, 2026, SonicWall disclosed two critical vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting SonicWall SMA1000 appliances, which are actively exploited. CVE-2026-83548, a pre-authentication SSRF vulnerability, has a CVSS score of 10.0, allowing unauthenticated remote access to sensitive functions. CVE-2026-83549 is an authenticated OS command injection vulnerability that can be exploited via the SSRF flaw for remote command execution.

SonicWall recommends immediate patching with platform hotfix versions 12.4.3-03526 and 12.5.0-02952, and advises organizations to check for signs of compromise due to prior exploitation. Affected SMA1000 models include 6210, 7210, and 8200v with specific vulnerable versions mentioned.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline