Illustrative image generated with AI
SonicWall SMA1000 Under Attack: Two Zero-Days Enable SSRF and System Command Execution
Two SonicWall SMA1000 zero-days (CVE-2026-83548, CVE-2026-83549) are actively exploited enabling SSRF and OS command execution. Learn affected models, hotfixes and CISA KEV guidance.
Text generated by artificial intelligence, published without human review. AI transparency
Exploitation Already Observed on Remote Access Appliances
Two zero-day vulnerabilities affect the SonicWall SMA1000 family, used as secure remote access gateways and SSL VPN appliances. SonicWall says it discovered both the vulnerabilities and their exploitation in real-world attacks.
The reported issues are CVE-2026-83548, a pre-authentication SSRF vulnerability, and CVE-2026-83549, an operating system command injection flaw. The simultaneous presence of both vulnerabilities in compromised environments suggests they may have been chained, although this has not been confirmed.
No details have been disclosed about the affected organizations, the attackers’ identities, or the operational procedures used during the intrusions. Indicators of compromise—including IP addresses, domains, hashes, or specific paths left by the attackers—are also unavailable.
For administrators, this is therefore not a matter of assessing a theoretical risk. Exploitation has already been observed, requiring both installation of the fixes and retrospective checks of exposed appliances.
From Pre-Authentication SSRF to Command Execution
CVE-2026-83548 affects the Appliance Work Place interface. It is a remotely exploitable Server-Side Request Forgery, or SSRF, vulnerability that requires no credentials and carries a CVSS score of 10.
The vulnerability stems from an unintended alternate access path. An attacker can cause the appliance to send requests to destinations or functions that would normally be inaccessible from the outside. This behavior may provide unauthorized access to sensitive components and enable prohibited operations.
An SSRF flaw in a remote access gateway is particularly critical because the appliance often sits between the Internet and internal resources. However, the details needed to determine which services can be reached through this specific vulnerability have not been published.
CVE-2026-83549, by contrast, is located in the Appliance Management Console (AMC). It requires an authenticated account but allows arbitrary commands to be injected into the operating system, potentially resulting in code execution. The listed score is CVSS 7.8, with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
In a chained attack scenario, the SSRF could theoretically be used to reach a protected function, while the injection flaw could then be used to issue system commands. It is not known, however, whether the observed attacks followed this sequence or how the attackers met the authentication requirement for the second vulnerability.
Vulnerable Models and Hotfixes to Install
The vulnerabilities affect three appliances in the SMA1000 family:
- SMA 6210;
- SMA 7210;
- SMA 8200v.
The fixes are available in the following hotfixes:
- 12.4.3-03526;
- 12.5.0-02952;
- all later versions that include the same fixes.
The exact earlier affected builds have not been disclosed. In the absence of this information, organizations should verify directly that every appliance is running at least one of the listed hotfixes rather than checking only the main version branch.
The alert should not automatically be extended to SonicWall’s entire product portfolio. The SSL VPN service integrated into SonicWall firewalls and appliances in the SMA100 series are not reported to be affected by these two zero-days.
No alternative workarounds to patching are available. Appliances directly exposed to the Internet should be prioritized, but installations reachable through intermediate networks or dedicated management interfaces also require review.
Two CVE Pairs Describe Similar Issues, but Their Relationship Remains Unclear
The identifier assignment contains a significant discrepancy. The newly reported vulnerabilities are identified as CVE-2026-83548 and CVE-2026-83549. However, the CISA Known Exploited Vulnerabilities catalog lists two SMA1000 issues with matching technical descriptions under the following identifiers:
- CVE-2026-15409, a remote unauthenticated SSRF vulnerability classified as CWE-918;
- CVE-2026-15410, a code injection vulnerability that allows an authenticated administrator to execute arbitrary commands, classified as CWE-94.
The relationship between the two pairs has not been publicly explained. It is therefore incorrect to automatically treat CVE-2026-83548 as equivalent to CVE-2026-15409, or to associate CVE-2026-83549 with CVE-2026-15410 without qualification.
There are also differences in the technical data. CVE-2026-15409 has a CVSS score of 10 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. CVE-2026-15410 has a CVSS score of 7.2 and the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, describing a remote attack that requires elevated privileges.
For CVE-2026-83548 and CVE-2026-83549, the available NVD entries do not yet include complete vectors, CWE classifications, or product versions. The CVSS 10 score assigned to the first vulnerability and the CVSS 7.8 score assigned to the second therefore do not come from complete NVD records.
This inconsistency requires caution in vulnerability management systems: searching for only one pair of identifiers could result in incomplete inventories or alerts.
The KEV Catalog Requires Patching and Forensic Analysis
The entries for CVE-2026-15409 and CVE-2026-15410 have been included in the CISA KEV catalog since July 14, 2026, with a remediation deadline of July 17, 2026 for U.S. federal agencies.
Both vulnerabilities are reported to have been used in ransomware campaigns. CISA also requires the forensic triage specified by BOD-26-04, in addition to applying the mitigations provided by the vendor. If fixes were unavailable, the guidance would be to consider product retirement in accordance with applicable requirements.
By contrast, CVE-2026-83548 and CVE-2026-83549 do not appear in KEV under those identifiers. This difference does not reduce the urgency: closely matching technical descriptions have already been associated by CISA with known exploitation and ransomware activity.
Administrators should therefore:
- immediately install 12.4.3-03526, 12.5.0-02952, or a later release;
- inventory SMA 6210, 7210, and 8200v appliances reachable from the Internet;
- inspect for anomalous requests to Appliance Work Place, possible SSRF behavior, and unauthorized operations;
- examine the AMC for unexpected commands or unrecognized administrative activity;
- subject potentially exposed appliances to forensic triage, without assuming that patching removes the consequences of a previous compromise;
- search their security tools for both groups of CVE identifiers.
Because no public indicators are available, the investigation must rely on the organization’s retained logs, configuration changes, administrative access records, and anomalous network behavior.
Another Episode in the Series of Exploited SonicWall Flaws
The CISA catalog returns 17 results when filtered for SonicWall. Previous incidents include CVE-2025-40602, an SMA1000 authorization flaw that can enable privilege escalation in the AMC. It has been listed in KEV since December 17, 2025, with a remediation deadline of December 24, 2025.
The SMA100 series has also been affected by the command injection vulnerabilities CVE-2023-44221 and CVE-2021-20035, added to KEV on May 1, 2025, and April 16, 2025, respectively. For SonicOS, the SSL VPN authentication bypass CVE-2024-53704 has been exploited in ransomware campaigns and has been listed in the catalog since February 18, 2025.
The operational takeaway is clear: patching the appliance is not enough if exploitation may already have occurred. The affected SMA1000 appliances require patching, exposure assessment, and coordinated forensic analysis.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-15409CRITICAL10.0A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- CVE-2024-53704CRITICAL9.8An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
- CVE-2026-83549HIGH7.8Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to
- CVE-2026-15410HIGH7.2Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
- CVE-2023-44221HIGH7.2Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
- CVE-2025-40602MEDIUM6.6A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
- CVE-2021-20035MEDIUM6.5Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
- CVE-2026-83548A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized oper
