SonicWall SMA1000 vulnerabilities (CVE-2026-83548, CVE-2026-83549) in active exploitation

On September 1, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected.

CVE-2026-83548 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface. According to the SonicWall advisory, an attacker could exploit this issue to “gain unauthorized access to sensitive functionality and perform unauthorized operations.” 

CVE-2026-83549 is a high-severity (CVSS score of 7.8) OS command injection vulnerability in the Appliance Management Console (AMC) that arises from improper neutralization of special elements. In specific conditions, it could “enable a remote attacker authenticated as an administrator to execute arbitrary OS commands, resulting in remote code execution.” 

SonicWall confirmed exploitation of these vulnerabilities in the wild.

Recommended actions

Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable SonicWall appliances in their environments and upgrade as appropriate as soon as possible. 

Sophos countermeasures

SophosLabs continues to monitor the threat landscape for activity related to these vulnerabilities and will deliver detections and protections as available.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.