ON September 1, 2026, SonicWall disclosed two critical vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting SonicWall SMA1000 appliances, which are actively exploited. CVE-2026-83548, a pre-authentication SSRF vulnerability, has a CVSS score of 10.0, allowing unauthenticated remote access to sensitive functions. CVE-2026-83549 is an authenticated OS command injection vulnerability that can be exploited via the SSRF flaw for remote command execution.
SonicWall recommends immediate patching with platform hotfix versions 12.4.3-03526 and 12.5.0-02952, and advises organizations to check for signs of compromise due to prior exploitation. Affected SMA1000 models include 6210, 7210, and 8200v with specific vulnerable versions mentioned.