SonicWall confirmed on September 1, 2026 that attackers are actively exploiting two previously undisclosed vulnerabilities in its SMA 1000 Series appliances, the hardware and virtual gateways thousands of enterprises use to grant employees remote access to internal networks. The flaws, tracked as CVE-2026-83548 and CVE-2026-83549, can be chained together to give an attacker with zero credentials a path to remote code execution on the box that sits directly between the public internet and a company’s internal systems. SonicWall has shipped hotfixes, but the advisory also tells administrators to check for signs their appliance was already compromised, reset every password and TOTP token, and in some cases re-image the device entirely.

This is the third confirmed wave of actively exploited SMA 1000 zero-days in just over a year, and it lands in a threat landscape where remote-access gateways from Ivanti, Citrix, and Palo Alto Networks have already taken turns as the industry’s most-abused entry point. Below is what SonicWall, SecurityWeek, Help Net Security, The Hacker News, Rapid7, and Sophos have confirmed so far, what remains unverified, and what it means for the security teams now racing to patch.

What Happened: SonicWall Confirms Active Exploitation of Two SMA 1000 Zero-Days

SonicWall published advisory SNWLID-2026-0016 on September 1, 2026, describing “multiple vulnerabilities” in the SMA 1000 Series and stating the flaws had been confirmed as actively exploited in the wild, according to SonicWall’s own advisory. Help Net Security reported the vendor confirmed the exploitation on Tuesday, writing that attackers were exploiting “two previously undisclosed vulnerabilities” in SMA 1000 appliances, per Help Net Security’s report. SecurityWeek and The Hacker News both published matching coverage on September 2, framing the pair as a chainable route to unauthenticated remote code execution.

The affected hardware is specific: only SMA 1000 Series models 6210, 7210, and 8200v, all running SonicWall’s Linux-based platform, are impacted. SonicWall and multiple outlets were explicit that the separate SMA 100 Series and SSL-VPN functionality built into SonicWall firewalls are not affected by these two CVEs, according to Help Net Security and SecurityWeek. That distinction matters for IT teams triaging exposure across mixed SonicWall fleets, since patch urgency differs sharply between the two product lines.

Neither SonicWall’s advisory nor the reporting reviewed for this piece names a specific threat actor or campaign behind the exploitation, and none of the outlets have published a hard count of how many appliances or organizations were hit. Those numbers, if they surface, would come from incident response firms or SonicWall itself in a follow-up disclosure. Until then, the scope should be treated as unconfirmed rather than assumed to be small.

CVE-2026-83548: The Critical Pre-Auth SSRF That Opens the Door

CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability in the Appliance Work Place interface of SMA 1000, and it carries the maximum possible severity score: a CVSS 10.0. SecurityWeek described it as letting a remote, unauthenticated attacker “access sensitive functionality and conduct unauthorized operations,” per SecurityWeek’s writeup. Threat-intelligence firm Ionix characterized it more bluntly, describing the bug as letting an unauthenticated attacker abuse an alternate access path so the appliance effectively turns itself into an unintended forward proxy.

SSRF bugs are dangerous specifically because they let an outsider make the vulnerable server perform requests on their behalf, often reaching internal services that were never meant to be internet-facing. In the SMA 1000 case, that means an attacker with no credentials at all can use the appliance to poke at functionality normally reachable only from inside the box, which is the first link in the exploitation chain that follows.

CVE-2026-83549: The Command Injection That Completes the Chain

The second flaw, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the Appliance Management Console, scored CVSS 7.8 (High) in SonicWall’s own advisory. Sophos described it as allowing an authenticated administrator, under specific conditions, “to execute arbitrary OS commands, resulting in remote code execution.” On its own, that requirement for an authenticated admin session limits the blast radius considerably.

The problem is that CVE-2026-83549 was not found on its own. Security research firm Rapid7 explained that while the command injection “on its own… requires an authenticated administrator and specific system conditions,” an attacker who first leverages the SSRF flaw, CVE-2026-83548, can potentially reach and abuse that same functionality “to execute arbitrary OS commands without prior authentication.” In other words, the authentication requirement that would normally contain CVE-2026-83549’s damage gets bypassed entirely once it’s paired with the first bug.

How Attackers Chain the Two Flaws for Unauthenticated RCE

Chaining is what turns two separately serious bugs into one critical incident. The sequence described across Rapid7’s and Ionix’s research runs roughly like this: an attacker with no credentials hits the Appliance Work Place interface and exploits the SSRF in CVE-2026-83548 to reach internal, normally unreachable functionality. From that foothold, they abuse the command injection path in CVE-2026-83549 that would ordinarily require an authenticated administrator session, and execute arbitrary operating system commands on the appliance. The end state is remote code execution on internet-facing infrastructure, achieved without a username or password.

That combination is precisely the profile that makes a vulnerability worth SonicWall’s maximum-urgency advisory language and worth CISA’s typical fast-tracking, even before any formal KEV catalog action shows up. A vendor doesn’t tell customers to consider re-imaging hardware and resetting every credential unless the exploitation path is both reliable and already being used against real targets.

Affected Products, Vulnerable Versions, and What’s Patched

SonicWall’s advisory lays out a clear version matrix. Appliances running platform-hotfix build 12.4.3-03453 or earlier, and those on 12.5.0-02835 or earlier, are vulnerable to both CVEs. The fix arrived in the same advisory: upgrading to 12.4.3-03526 or higher, or 12.5.0-02952 or higher, remediates both flaws. The table below summarizes the two vulnerabilities side by side.

DetailCVE-2026-83548CVE-2026-83549
CVSS score10.0 (Critical)7.8 (High)
Vulnerability typePre-auth server-side request forgery (SSRF)Post-auth OS command injection
Affected componentAppliance Work Place interfaceAppliance Management Console (AMC)
Authentication requiredNoneAdministrator session (bypassable when chained with 83548)
ImpactTurns appliance into unauthorized forward proxy; reaches internal-only functionalityArbitrary OS command execution / remote code execution
Affected modelsSMA 1000 (6210, 7210, 8200v), all hypervisorsSMA 1000 (6210, 7210, 8200v), all hypervisors
Vulnerable versions12.4.3-03453 and earlier; 12.5.0-02835 and earlier12.4.3-03453 and earlier; 12.5.0-02835 and earlier
Patched versions12.4.3-03526 and higher; 12.5.0-02952 and higher12.4.3-03526 and higher; 12.5.0-02952 and higher

Notably, SMA 100 Series appliances and the SSL-VPN feature built into SonicWall’s firewall line sit outside the vulnerable version matrix entirely. Organizations running a mixed environment of SMA 1000 gateways alongside SMA 100 or firewall-based remote access should confirm which product line each deployment actually uses before assuming they’re covered, since the naming similarity between SMA 100 and SMA 1000 has caused confusion in past SonicWall advisories.

SonicWall’s Patch and Incident Response Guidance

SonicWall’s advisory instructs every organization running SMA 1000 on an affected build to upgrade to the latest hotfix through the customer portal immediately. That’s the baseline step. What sets this advisory apart from a routine patch notice is the second half of the guidance, aimed at organizations that may already have been compromised before the hotfix existed.

SonicWall recommends contacting its technical support team to review systems for indicators of compromise, and if any are found, taking the more drastic step of re-imaging hardware appliances or redeploying virtual ones from a clean state rather than trusting an in-place patch. The advisory also calls for changing all user and administrator passwords and resetting TOTP multi-factor tokens, on the assumption that credentials handled by a compromised appliance should no longer be trusted. Rapid7’s own brief echoed the same sequence: patch immediately, then review logs and reset credentials as standard post-incident hygiene.

SonicWall SMA 1000 remediation checklist (per SNWLID-2026-0016):
1. Confirm model: SMA 1000 (6210 / 7210 / 8200v) vs SMA 100 — only SMA 1000 is affected
2. Check current platform-hotfix build against the vulnerable list
   Vulnerable: 12.4.3-03453 or earlier | 12.5.0-02835 or earlier
3. Upgrade via SonicWall customer portal to:
   12.4.3-03526 or higher | 12.5.0-02952 or higher
4. Contact SonicWall support to review logs for indicators of compromise
5. If IoCs are found: re-image hardware / redeploy virtual appliance from clean state
6. Reset all user and administrator passwords
7. Reset all TOTP / MFA tokens tied to the appliance

Historical Context: SMA 1000’s Third Zero-Day Wave in 14 Months

This isn’t the first time SMA 1000 has been caught in active exploitation this year. In July 2026, SonicWall disclosed CVE-2026-15409 and CVE-2026-15410, another SSRF pairing in the same product line, also actively exploited and also rated CVSS 10.0. That earlier campaign was notable for something September’s advisory hasn’t reported: Rapid7 documented attackers dropping a custom Python-based malware payload, tracked as KNUCKLEBALL, directly onto compromised SMA 1000 appliances. Watershed information-sharing group WaterISAC circulated a notice on the July flaws describing the same pattern of confirmed exploitation and emergency hotfixes.

Not every SMA 1000 disclosure this year involved active exploitation. An April 2026 SonicWall product notice covering other, medium-severity SMA 1000 issues explicitly stated the company was “not aware of active exploitation in the wild” and had received no reports of malicious use for those particular bugs. That contrast is useful: it shows SonicWall does distinguish exploited zero-days from routine patched vulnerabilities in its own communications, which makes the “confirmed actively exploited” language in both the July and September advisories carry real weight rather than boilerplate caution.

Two confirmed-exploited zero-day waves against the same appliance line within 14 months point to sustained attacker interest in SMA 1000 specifically, rather than a one-off discovery. Security teams that patched in July should not assume that action covers them now; September’s CVE-2026-83548 and CVE-2026-83549 are separate, unrelated vulnerabilities requiring their own hotfix.

Competitive Comparison: How Rival Remote-Access Vendors Stack Up

SonicWall is not alone in having its remote-access hardware turned into an attacker’s front door in the past 20 months. Ivanti disclosed CVE-2025-0282, a stack-based buffer overflow in Connect Secure, Policy Secure, and Neurons for ZTA Gateways, in January 2025, rated CVSS 9.0 and exploited on a limited number of appliances before a patch existed. Citrix had a rougher stretch in mid-2025: reporting tracked by CyberScoop describes the company disclosing three actively exploited zero-days in a matter of weeks, including CVE-2025-5777, a memory-overread bug in NetScaler ADC and NetScaler Gateway nicknamed “CitrixBleed 2” and scored CVSS 9.8, alongside CVE-2025-6543 and a later critical flaw, CVE-2025-7775, affecting the same NetScaler product line. Palo Alto Networks’ GlobalProtect portal and gateway, part of PAN-OS, saw its own critical authentication-bypass flaw, CVE-2026-0257, used in real-world intrusions and reported by Arctic Wolf in June 2026.

The pattern across all five vendors is consistent: internet-facing remote-access and VPN gateways, precisely because they’re designed to be reachable from anywhere and to hold privileged network access once authenticated, have become the software category attackers prioritize for zero-day research. SonicWall’s second and third SMA 1000 waves this year fit squarely inside that broader trend rather than standing apart from it.

Vendor / ProductCVECVSSDisclosedFlaw type
SonicWall SMA 1000CVE-2026-83548 / 8354910.0 / 7.8Sept. 2026SSRF chained to command injection
SonicWall SMA 1000CVE-2026-15409 / 1541010.0July 2026SSRF pair, KNUCKLEBALL malware dropped
Palo Alto GlobalProtect (PAN-OS)CVE-2026-0257CriticalJune 2026Authentication bypass
Citrix NetScaler ADC/GatewayCVE-2025-7775CriticalAug. 2025Actively exploited zero-day
Citrix NetScaler ADC/GatewayCVE-2025-5777 (“CitrixBleed 2”)9.8June 2025Memory overread
Ivanti Connect Secure / Policy SecureCVE-2025-02829.0Jan. 2025Stack-based buffer overflow

Why Remote Access Gateways Keep Becoming the Entry Point

There’s a structural reason these appliances keep showing up in exploitation advisories rather than, say, internal file servers or employee laptops. A remote-access gateway has to be reachable from the open internet by design, since its entire purpose is letting employees connect from outside the corporate network. That same requirement means it can’t be hidden behind a firewall the way most internal infrastructure can be, and it typically holds elevated trust once a session is established, since the whole point of the device is to broker access into everything behind it.

Combine that exposure with the fact that these are closed appliances running vendor-specific code that security teams can’t easily audit themselves, and you get a category where a single chained bug, like the SSRF-to-RCE path in CVE-2026-83548 and CVE-2026-83549, can compromise the perimeter of an otherwise well-defended network. That’s also why SonicWall’s guidance goes beyond “install the patch” into forensic review and credential resets: a compromised gateway can’t be trusted to have kept anything behind it safe.

Where the CISA KEV Catalog Fits

As of this writing, there is no public confirmation that CVE-2026-83548 or CVE-2026-83549 have been added to CISA’s Known Exploited Vulnerabilities catalog, and no dated KEV entry has surfaced in the reporting reviewed for this piece. That’s worth flagging explicitly rather than assuming, since a KEV listing carries real weight for federal agencies operating under Binding Operational Directive patch deadlines and often accelerates enterprise patch prioritization more broadly.

Given that SonicWall itself has confirmed active exploitation, and given the pattern from the July 2026 SMA 1000 zero-days, a KEV addition would not be surprising in the days ahead. Security teams shouldn’t wait for that listing to act, though. SonicWall’s own advisory already carries the “actively exploited” confirmation that normally triggers KEV inclusion, and treating the hotfix as urgent regardless of catalog status is the safer call.

Market and Enterprise Impact

For enterprises running SMA 1000 as their primary remote-access gateway, this advisory forces an unplanned emergency change window: patching, log review, and potentially credential rotation across every account that touched the appliance. That’s disruptive even when it goes smoothly, and it lands on security teams that, in many cases, were still working through the July 2026 SMA 1000 response just two months earlier.

There’s also a vendor-trust dimension. Two confirmed-exploited zero-day waves against the same product line inside 14 months is the kind of pattern that pushes some enterprise buyers to at least evaluate alternatives at renewal time, even if SonicWall’s disclosure and remediation process itself has been prompt and transparent. Whether that translates into actual vendor churn is impossible to quantify from public reporting, but it’s a real conversation happening inside security teams that rely on SMA 1000 for business-critical access.

Detection: What to Look For If You Run SMA 1000

Because SonicWall’s advisory doesn’t publish specific indicators of compromise in the public version of SNWLID-2026-0016, the practical starting point for administrators is the same forensic posture the vendor itself recommends: engage SonicWall technical support directly for an appliance-specific review rather than relying on generic log-scanning advice. Rapid7’s guidance for customers points in the same direction, treating the two CVEs as active-incident material rather than a routine patch-and-move-on scenario.

What administrators can do immediately, without waiting on vendor support tickets, is confirm exposure using the version matrix above, isolate any SMA 1000 appliance still running a vulnerable build if it can’t be patched right away, and start the credential-reset process SonicWall recommends even before a compromise is confirmed. Given the low cost of resetting passwords and TOTP tokens compared to the cost of a missed compromise, most security teams are treating that step as mandatory rather than optional.

Predictions: What Happens Next

A few outcomes look likely in the days and weeks ahead, based on how similar advisories have played out this year and in 2025. First, expect CISA to add CVE-2026-83548 and, likely, CVE-2026-83549 to the KEV catalog given SonicWall’s own confirmation of active exploitation; that pattern held for the July 2026 SMA 1000 pair and for comparable Citrix and Ivanti disclosures.

Second, watch for a named malware family tied to this campaign the way KNUCKLEBALL got attached to the July incident; incident responders typically publish that detail once enough compromised appliances have been forensically examined. Third, expect enterprise SMA 1000 patch rates to lag behind the urgency of the advisory, as they typically do with appliance patches that require a maintenance window rather than an automatic update. Fourth, given the back-to-back SMA 1000 waves, SonicWall will likely face pointed questions at its next security disclosure or earnings call about what changed in its secure development lifecycle for that product line. Fifth, expect competitors, particularly Ivanti and Citrix, both still working to rebuild trust after their own 2025 zero-day waves, to use this moment in their own marketing to position their platforms as the more scrutinized alternative, even though the data above shows the entire remote-access appliance category has had a rough stretch.

What This Means for Security Teams Right Now

If your organization runs SMA 1000 6210, 7210, or 8200v on any hypervisor, treat this as an active-incident response task, not a routine patch cycle. Confirm your build number against the vulnerable-versions list, patch to 12.4.3-03526 or 12.5.0-02952 or later immediately, and follow through on SonicWall’s password and TOTP reset guidance even if you find no direct evidence of compromise. The cost of that caution is far lower than the cost of an attacker who chained an SSRF into command execution on the one appliance that sits between your network and the open internet.

Frequently Asked Questions

What is CVE-2026-83548?

CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in the Appliance Work Place interface of SonicWall SMA 1000, rated CVSS 10.0 and confirmed as actively exploited in SonicWall’s September 1, 2026 advisory.

What is CVE-2026-83549?

CVE-2026-83549 is a post-authentication OS command injection vulnerability in the SMA 1000’s Appliance Management Console, rated CVSS 7.8. When chained with CVE-2026-83548, it can be triggered without prior authentication, resulting in remote code execution.

Which SonicWall products are affected?

Only SMA 1000 Series models 6210, 7210, and 8200v, running any hypervisor, on platform-hotfix builds 12.4.3-03453 or earlier, or 12.5.0-02835 or earlier. SMA 100 Series appliances and SSL-VPN on SonicWall firewalls are not affected by these two CVEs.

Are CVE-2026-83548 and CVE-2026-83549 in the CISA KEV catalog?

As of this writing, no public source confirms these CVEs have been added to CISA’s Known Exploited Vulnerabilities catalog. Given SonicWall’s own confirmation of active exploitation, an addition would not be unexpected, but it should not be treated as fact until CISA publishes it.

How do I patch my SMA 1000 appliance?

Upgrade to platform-hotfix build 12.4.3-03526 or higher, or 12.5.0-02952 or higher, through the SonicWall customer portal, as specified in advisory SNWLID-2026-0016.

Is this the same as the SMA 1000 zero-days disclosed in July 2026?

No. The July 2026 disclosure covered CVE-2026-15409 and CVE-2026-15410, a separate SSRF pair also rated CVSS 10.0, tied to a custom malware payload called KNUCKLEBALL. CVE-2026-83548 and CVE-2026-83549 are distinct vulnerabilities requiring their own patch.

What should I do if I suspect my SMA 1000 was already compromised?

Contact SonicWall technical support to review the appliance for indicators of compromise. If any are found, SonicWall recommends re-imaging hardware appliances or redeploying virtual ones from a clean state, then resetting all user and administrator passwords and TOTP tokens.

How many organizations or devices have been affected?

No named source has published a specific count of affected devices or organizations for CVE-2026-83548 and CVE-2026-83549 as of this writing. SonicWall and multiple outlets have confirmed active exploitation without disclosing scope.