Vulnerability
Published 2026-09-02
Verified 2026-09-19

SonicWall SMA1000: two zero-days chained for unauth RCE (CVE-2026-83548, CVE-2026-83549); CISA KEV

SonicWall's 2 September 2026 advisory SNWLID-2026-0016 (covered by SecurityWeek the same day) warns SMA1000 series secure remote access / SSL-VPN customers of two zero-days discovered and observed exploited internally. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface, rated CVSS 10. CVE-2026-83549 is an OS command injection in the Appliance Management Console (AMC), rated CVSS 7.8, that an authenticated attacker can use for arbitrary OS commands and potential RCE. SonicWall says both have been exploited and the pair can be chained for unauthenticated remote code execution. Affected models: SMA1000 6210, 7210 and 8200v. Hotfixes 12.4.3-03526, 12.5.0-02952 and higher patch both issues. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected. CISA added both CVEs to the KEV catalog on 2 September 2026.

Product
SonicWall SMA1000 (6210, 7210, 8200v)
Versions
SMA1000 series before hotfixes 12.4.3-03526 / 12.5.0-02952; firewall SSL-VPN and SMA100 not affected
CVSS
10.0 (CVE-2026-83548); 7.8 (CVE-2026-83549) — per SecurityWeek citing SonicWall
Exploited in Australia?
unknown
Patch to
Hotfixes 12.4.3-03526, 12.5.0-02952 or higher

Primary: SonicWall PSIRT SNWLID-2026-0016 · Vendor: SonicWall PSIRT · CVE: CVE-2026-83548, CVE-2026-83549 · CISA KEV alert (2 Sep 2026; CVE-2026-83548/83549)

vulnerabilities network