SonicWall warns customers of two actively exploited flaws in SMA 1000 appliances

02 Sep 2026

SonicWall has recently published an advisory regarding two actively exploited vulnerabilities (one critical and one high severity) in its Secure Mobile Access 1000 series (6210, 7210, and 8200v).

 

Through the blog, we will understand what the vulnerabilities in SonicWall SMA 1000 appliances are about, the threats posed by them, and what organizations can do to defend against them.

About the vulnerabilities

Vendor + components affected 

CVE/CVSS/Type 

About 

Disclosed  

Impacted versions  

Fixed versions 

 

SonicWall + Secure Mobile Access 1000 

(6210, 7210, and 8200v). 

CVE-2026-83548/10 

(Critical)/Pre-authentication SSRF via unintended forward proxy 

 

CVE-2026-83549/7.8(High)/Post-authentication Remote Code Execution (RCE) 

CVE-2026-83548 is an SSRF vulnerability that exists in the Appliance Work Place interface of SMA 1000 due to an unintended alternative access path. 

 

CVE-2026-83549 is a post-authentication Remote Code Execution (RCE) flaw that exists in the Appliance Management Console of SMA 1000.  

 

Both vulnerabilities are actively being exploited by attackers. 
 

 

  

September 1, 2026 

12.4.3-03453 (all versions) 

 

12.5.0-02835 (all versions) 

 

12.4.3-03526  

 

 

12.5.0-02952  

 

What can attackers do with the vulnerabilities?

Vulnerability  

What can an attacker do? 

CVE-2026-83548 

  • Gain remote unauthorized access to sensitive appliance functionality. 
  • Bypass intended access restrictions. 
  • Access internal service or resources through the appliance. 
  • Perform unauthorized operations without authentication. 
  • Can use the flaw for initial access or to carry out multi-stage attack. 

CVE-2026-83549 

  •  Gain unauthorized access to the SMA1000 appliance without authentication 
  • Execute arbitrary OS commands and engage in remote code execution 
  • Obtain privileged/root-level control of the appliance 
  • Deploy web shells, malware 
  • Establish persistence mechanisms 
  • Modify files/security configurations and maintain access 
  • Use the remote access as a foothold for orchestrating internal networks and systems 

 

These vulnerabilities are particularly dangerous because they can be combined in an attack chain to remotely execute malicious code.

 

Any compromise of SMA1000 instance should be treated as a high-impact compromise.

SharkStriker’s recommendations

  • Immediately patch affected SMA1000 appliances.
  • Review appliance logs for suspicious activity.
  • If compromise is confirmed, re-image/re-deploy the appliance, change user/admin passwords, and reset TOTP tokens.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE