SonicWall disclosed active exploitation of two vulnerabilities in SMA1000-series SSL VPN appliances: CVE-2026-83548, a critical pre-authentication server-side request forgery (SSRF) flaw with a CVSS score of 10.0, and CVE-2026-83549, a high-severity post-authentication OS command-injection flaw. The SSRF issue stems from an unintended forward-proxy access path in the Work Place interface and may enable unauthenticated attackers to reach internal resources or potentially execute commands; the command-injection flaw enables authenticated administrators to run arbitrary operating-system commands through the Appliance Management Console.
SonicWall has issued hotfix firmware and urged customers to apply it immediately. Organizations operating affected appliances should restrict access to the Work Place and administrative interfaces, monitor appliances for anomalous outbound connections, and review administrator activity and appliance logs for indicators of compromise.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
CISA added SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 to its Known Exploited Vulnerabilities catalog after SonicWall reported both flaws were being actively exploited.
The Canadian Centre for Cyber Security published advisory AV26-872 concerning active exploitation of CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA1000 appliances. It identified affected SMA1000 6210, 7210, and 8200v devices and urged administrators to apply available updates and review SonicWall guidance.
SonicWall released SMA1000 hotfix firmware versions 12.4.3-03526 and 12.5.0-02952 to address CVE-2026-83548 and CVE-2026-83549, urging customers to upgrade promptly.
SonicWall PSIRT disclosed CVE-2026-83548, a CVSS 10.0 pre-authentication SSRF flaw in the SMA1000 Work Place interface, and CVE-2026-83549, a post-authentication OS command-injection flaw in the Appliance Management Console. PSIRT said its investigation of a case indicated that the vulnerabilities were being actively exploited.
CISA confirmed in August that ransomware gangs were abusing SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410, which attackers had exploited in July to install custom malware on VPN appliances.
A Metasploit module, linux/http/sonicwall_sma1000_couchdb_rce, was added for SMA1000-9427. It abuses SonicWall WorkPlace to proxy unauthenticated requests to loopback CouchDB, enables CouchDB's Erlang query server, and demonstrated a root Meterpreter session through ctrl-service and cmsSnmpTrap.sh.
WaterISAC notified affected utilities that the actively exploited CVE-2026-83548 and CVE-2026-83549 chain requires immediate installation of SonicWall hotfix firmware, with no workaround available. It warned that compromise of internet-facing SMA1000 gateways could provide access to internal and potentially OT-supporting environments.
Truesec advised defenders to review SMA1000 syslogs for POST requests to /workplace/ containing URL-encoded internal IP addresses, loopback addresses, or management hostnames, and to investigate Appliance Management Console access originating from the appliance workplace process. It also highlighted suspicious requests involving /workplace/, /appliance/, and 127.0.0.1.
NHS England published an advisory warning that internet-facing edge devices are attractive targets and rapidly exploited. Its National CSOC assessed further exploitation of CVE-2026-83548 and CVE-2026-83549 as almost certain.
SonicWall advised customers to have affected systems reviewed for indicators of compromise. For confirmed compromises, it recommended re-imaging physical SMA1000 appliances or re-deploying virtual appliances, changing user and administrator passwords, and resetting TOTP tokens.
SonicWall said observed exploitation of CVE-2026-83548 and CVE-2026-83549 suggests attackers may be chaining the flaws. The SSRF and command-injection chain can enable unauthenticated remote code execution on affected SMA1000 appliances.
Huntress reported that an attack spree in late July compromised 30 SonicWall customers in less than two days. The report provides a quantified victim impact for the earlier SMA1000 exploitation activity.
More than a month before the newly disclosed flaws, SonicWall fixed SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410. The earlier vulnerabilities were reportedly exploited by UTA0533 to deploy KNUCKLEBALL malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
41 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecert.pa
Open sourcegithub.com
Open sourcehipaajournal.com
Open sourcelabs.beazley.security
Open sourcecve.org
Open sourcepsirt.global.sonicwall.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.