SonicWall warns of two SMA1000 zero-days exploited
SonicWall alerts customers that two SMA1000 flaws-CVE-2026-83548 (pre-auth SSRF) and CVE-2026-83549 (auth OS command injection)—are being actively exploited.
SonicWall published an advisory on Tuesday saying two zero-day vulnerabilities in its SMA1000 secure remote access gateway are being exploited in the wild. The vendor reports the flaws were discovered internally and that it has observed active exploitation.
The first flaw, CVE-2026-83548, carries a CVSS score of 10 and is a pre-authentication server-side request forgery (SSRF) in the Appliance Work Place interface. An unauthenticated attacker can trigger SSRF to reach sensitive functionality and perform unauthorized operations. The second flaw, CVE-2026-83549, has a CVSS score of 7.8 and is an operating-system command injection in the Appliance Management Console (AMC). An authenticated user can exploit it to execute arbitrary OS commands, which can lead to remote code execution.
SonicWall’s advisory indicates the two vulnerabilities have been chained in observed attacks. The SMA1000 models identified as affected are 6210, 7210 and 8200v. The advisory notes that SSL-VPN functions on SonicWall firewall products and SMA100 series appliances are not affected.
Hotfix builds that remediate the issues are 12.4.3-03526, 12.5.0-02952 and later; SonicWall advises customers to install those updates. The public advisory does not include indicators of compromise or technical exploit details. The U.S. Known Exploited Vulnerabilities catalog has not yet added these CVEs; it currently lists 17 SonicWall product vulnerabilities.
Organizations running affected SMA1000 appliances are advised to review the advisory and apply the listed hotfixes promptly.








