Executive Summary

    On September 1, 2026 SonicWall PSIRT disclosed two critical vulnerabilities affecting SMA1000 series appliances. Tracked as CVE-2026-83548 and CVE-2026-83549, SonicWall confirmed that the vulnerabilities are being actively exploited in the wild.

    CVE-2026-83548 is a critical pre-authentication Server-Side Request Forger (SSRF) flaw scoring CVSS 10, while CVE-2026-83549 is a high-severity post-authentication OS command injection vulnerability.

    Given active exploitation in the wild, Beazley Security recommends affected organizations apply available hotfixes immediately and conduct a review for any signs of compromise.

    Affected Systems or Products

    Product

    Affected Versions

    Fixed Versions

    SMA1000 Models (6210, 7210 & 8200v)

    12.4.3-03453 (platform-hotfix) and older versions

    12.5.0-02835 (platform-hotfix) and older versions

    12.4.3-03526 (platform-hotfix)

    12.5.0-02952 (platform-hotfix)

    Mitigations / Workarounds

    Given active exploitation in the wild, Beazley Security strongly recommends organizations apply updates immediately. SonicWall has released hotfixes to remediate these vulnerabilities. Please see the “patches” section for more information.

    If patching cannot be applied, other mitigations may temporarily reduce risk of exposure:

    • Temporarily limit access to the Workplace interface to trusted, administrative networks.

    • Restrict access to the SMA1000 Appliance Management Console (AMC) to trusted IP addresses and admin networks only.

    • Monitor for anomalous outbound connections from SMA1000 appliances that may indicate SSRF exploitation.

    • Review administrator-level account activity on the AMC for signs of unauthorized command execution.

    Patches

    SonicWall has released hotfix firmware that addresses both vulnerabilities. Additional details are available in the official SonicWall advisory and fixes are available for download at mysonicwall.com.

    Indicators of Compromise

    SonicWall PSIRT has investigated a case confirming active exploitation of these vulnerabilities. However, no specific threat actor attribution, public proof-of-concept exploit or detailed indicators of compromise were made available at the time of this writing.

    Technical Details

    SMA1000 appliances are SSL VPN gateways that provide secure remote access to enterprise networks, making them high-value targets for threat actors seeking an initial foothold. SonicWall remote access products have repeatedly been targeted through both zero-day and previously disclosed vulnerabilities to gain access to victim environments.

    CVE-2026-83548 is a critical pre-authentication SSRF vulnerability present in the SMA1000 Appliance Workplace interface. The vulnerability is scored at a max CVSS v3 10 and potentially allows a remote, unauthenticated attacker to reach internal resources or execute unauthorized commands. Additional details have not been released by SonicWall at the time of this writing.

    CVE-2026-83549 is an OS command injection vulnerability identified in the SMA1000 appliance management console (AMC). Under specific conditions, it enables a remote authenticated attacker with administrator permissions to execute arbitrary OS commands, resulting in remote code execution.

    At the time of writing, SonicWall has not publicly disclosed the exploitation techniques or the specific relationship between the two vulnerabilities beyond confirming their use in active attacks. It cannot be discounted that the pre-authentication SSRF vulnerability may be chained with CVE-2026-83549. Successful exploitation of CVE-2026-83549 results in arbitrary command execution on the underlying operation system.

    How Beazley Security is responding

    Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

    We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

    If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.