SonicWall SMA1000 Series: Critical Vulnerability Exploited (Sept. 2026)

Sicherheit (Pexels, allgemeine Nutzung)[German]Since September 1, 2026, SonicWall, CERT Austria, and CERT Germany have been warning about two critical vulnerabilities (CVE-2026-83548, CVE-2026-83549) in the SMA1000 Series from SonicWall. Unpatched instances of the Secure Mobile Access (SMA) 1000 Series are currently under attack. However, security updates in the form of hotfixes are available for the affected SMA1000 Series appliances.

What is the SonicWall SMA1000 Series?

The SonicWall Secure Mobile Access (SMA) 1000 Series is a SonicWall solution for secure and scalable remote access (VPN) by employees to corporate resources. The SonicWall SMA1000 Series is suitable for medium to very large organizations and government agencies to manage a large number of external connections. The series includes physical appliances and virtual instances (such as the SMA 6210, 7210, or 8200v).

Warning About Attacks

There are two serious security vulnerabilities in SonicWall's SMA1000 Series appliances (CVE-2026-83548, CVE-2026-83549).

  • CVE-2026-83548: (CVSS 3.x Base Score 10.0, critical); The Work-Place interface of the SMA1000 appliance contains a pre-authentication SSRF vulnerability caused by an unintended alternative access path. An unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functions and perform unauthorized operations.
  • CVE-2026-83549: (CVSS 3.x Base Score 7.8, high); A vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) where, after authentication, specific elements used in an operating system command are not properly sanitized ("OS Command Injection"). Under certain circumstances, this could allow an authenticated attacker to remotely execute arbitrary operating system commands as an administrator, which could lead to remote code execution.

The more severe of the two vulnerabilities allows attackers to remotely and without authentication trick the appliance into sending server-side requests to internal endpoints that are normally unreachable (Server-Side Request Forgery).

SonicWall published a PSIRT PSIRT SNWLID-2026-0016 on September 1, 2026, stating that the vulnerabilities described in this advisory are already being actively exploited. The affected SMA1000 models are 6210, 7210, and 8200v in the following versions:

  • 12.4.3-03453 (platform-hotfix) and earlier versions.
  • 12.5.0-02835 (platform-hotfix) and earlier versions.

According to the manufacturer, SSL-VPN on SonicWall firewalls and the SMA 100 Series product line are not affected by these vulnerabilities. SonicWall provides a platform hotfix for affected models that resolves the vulnerabilities:

  • 12.4.3-03526 (platform-hotfix) and higher.
  • 12.5.0-02952 (platform-hotfix) and higher.

Since there are no workarounds, and SonicWall has observed active exploitation of the vulnerabilities described, we recommend installing the available hotfixes as soon as possible.

This entry was posted in devices, Security, Software, Update and tagged , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

Note: Please note the rules for commenting on the blog (first comments and linked posts end up in moderation, I release them every few hours, I rigorously delete SEO posts/SPAM).