Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Alert! Hackers actively targeting pair of vulnerabilities in SonicWall SMA1000 appliances

CVE-2026-83548 and CVE-2026-83549 could give attackers complete control of a target device, as experts warn customers to prioritise patching.

Fri, 04 Sep 2026
Alert! Hackers actively targeting pair of vulnerabilities in SonicWall SMA1000 appliances

Internet appliance firm SonicWall disclosed a pair of vulnerabilities in its SMA1000 series devices, with hackers already exploiting them.

CVE-2026-83548 is a pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface with a CVSS score of 10, while CVE-2026-83549 is a command injection vulnerability in the SMA1000 Appliance Management Console.

Both were disclosed on 1 September, with SonicWall saying it was investigating at least one case of exploitation.

 
 

The vulnerabilities impact SMA1000 Models 6210, 7210, and 8200v, running 12.4.3-03453 and older versions, as well as 12.5.0-02835 and older versions.

“Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability,” SonicWall said at the time.

Cyber security firm Rapid7 released an Emergent Threat Response blog soon after, which was updated on 3 September, explaining why patching should be a priority.

“SonicWall SMA1000 appliances are enterprise secure remote access gateways used to provide employees and other authorised users with access to internal applications and resources,” Rapid7 said.

“Their role as network-edge systems makes successful exploitation particularly concerning, since affected Work Place interfaces may be exposed directly to the internet as part of normal deployment.”

Unfortunately, the timing of the disclosure is also problematic.

“Because exploitation was occurring before public disclosure, organisations should not rely solely on patching to determine whether an appliance has already been compromised,” Rapid7 said.

SonicWall recommends upgrading affected appliances to:

  • 12.4.3-03526 platform-hotfix, for systems on the 12.4.3 branch
  • 12.5.0-02952 platform-hotfix, for systems on the 12.5.0 branch

Jake Knott, head of threat intelligence at exposure management firm watchTowr, said SonicWall’s disclosure of issues with such a vital piece of internet infrastructure was part of the “perpetual Groundhog Day that is cyber security”.

“Please, stop us if you’ve heard this one before (but it might sound oddly familiar). Another appliance sitting at the edge of the network, another pair of vulnerabilities chained together, and another unauthenticated path to complete compromise,” Knott told Cyber Daily.

“CVE-2026-83548 is a Server-Side Request Forgery that allows an unauthenticated attacker to reach sensitive functionality, while CVE-2026-83549 provides the Remote Code Execution needed to take control of the appliance. The vulnerabilities may sound less alarming when described separately. But chain them together? The outcome is straight-up painful.”

Knott also questioned SonicWall’s own reporting of the vulnerabilities.

“SonicWall says these vulnerabilities were internally discovered, while also saying it investigated a case indicating active exploitation,” Knott said.

“Please pick one, or, at minimum, explain how both are true. Those statements may be technically accurate, but without that context, the disclosure leaves defenders guessing about when and how the vulnerabilities were actually identified.”

According to Knott, the bottom-line issue is that routine patching is simply not enough in this case.

“Organisations running affected SMA1000 appliances should upgrade immediately and investigate any exposed systems for evidence of compromise,” Knott said.

“SonicWall’s own guidance goes considerably further than applying a hotfix, suggesting that where indicators are found, organisations should reimage or redeploy the appliance, change user and administrator passwords, and reset TOTP tokens. Other than that, have a great Wednesday.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: