SonicWall SMA1000: two zero-days chained for unauth RCE (CVE-2026-83548, CVE-2026-83549); CISA KEV
SonicWall's 2 September 2026 advisory SNWLID-2026-0016 (covered by SecurityWeek the same day) warns SMA1000 series secure remote access / SSL-VPN customers of two zero-days discovered and observed exploited internally. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface, rated CVSS 10. CVE-2026-83549 is an OS command injection in the Appliance Management Console (AMC), rated CVSS 7.8, that an authenticated attacker can use for arbitrary OS commands and potential RCE. SonicWall says both have been exploited and the pair can be chained for unauthenticated remote code execution. Affected models: SMA1000 6210, 7210 and 8200v. Hotfixes 12.4.3-03526, 12.5.0-02952 and higher patch both issues. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected. CISA added both CVEs to the KEV catalog on 2 September 2026.
- Product
- SonicWall SMA1000 (6210, 7210, 8200v)
- Versions
- SMA1000 series before hotfixes 12.4.3-03526 / 12.5.0-02952; firewall SSL-VPN and SMA100 not affected
- CVSS
- 10.0 (CVE-2026-83548); 7.8 (CVE-2026-83549) — per SecurityWeek citing SonicWall
- Exploited in Australia?
- unknown
- Patch to
- Hotfixes 12.4.3-03526, 12.5.0-02952 or higher
Primary: SonicWall PSIRT SNWLID-2026-0016 · Vendor: SonicWall PSIRT · CVE: CVE-2026-83548, CVE-2026-83549 · CISA KEV alert (2 Sep 2026; CVE-2026-83548/83549)
