---
title: SonicWall SMA1000 Zero-Days CVE-2026-83548 & CVE-2026-83549 Under Active Exploitation
description: SonicWall confirms two actively-exploited SMA1000 zero-days (CVE-2026-83548, CVE-2026-83549) chainable to unauthenticated RCE. Who's affected and what to do.
image: https://blog.openvpn.net/hubfs/blog-images/sonicwall-sma1000-cve-2026-83548-83549-header.png
---

- [Blog](https://blog.openvpn.net)
- [Cybersecurity](https://blog.openvpn.net/tag/cybersecurity)

# SonicWall SMA1000 Zero-Days CVE-2026-83548 & CVE-2026-83549 Under Active Exploitation

Oct 8, 2026 •  4 min read

![Two remote-access appliances: one opened up for emergency patching with its connection cut, the other independent gateway still keeping a remote laptop connected](https://blog.openvpn.net/hubfs/blog-images/sonicwall-sma1000-cve-2026-83548-83549-header.png)

Share

- <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.openvpn.net%2Fsonicwall-sma1000-cve-2026-83548-83549&title=SonicWall%20SMA1000%20Zero-Days%20CVE-2026-83548%20%26amp%3B%20CVE-2026-83549%20Under%20Active%20Exploitation&summary=SonicWall+confirms+two+actively-exploited+SMA1000+zero-days+%28CVE-2026-83548%2C+CVE-2026-83549%29+chainable+to+unauthenticated+RCE.+Who%27s+affected+and+what+to+do.&source=>
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.openvpn.net%2Fsonicwall-sma1000-cve-2026-83548-83549>
- <https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.openvpn.net%2Fsonicwall-sma1000-cve-2026-83548-83549&text=SonicWall+SMA1000+Zero-Days+CVE-2026-83548+%26amp%3B+CVE-2026-83549+Under+Active+Exploitation>
- <https://blog.openvpn.net/sonicwall-sma1000-cve-2026-83548-83549>

By Adam Bullock

SonicWall has confirmed that two previously undisclosed vulnerabilities in its SMA1000 remote-access appliances are being actively exploited in the wild. 

This post covers what CVE-2026-83548 and CVE-2026-83549 are, which appliances are affected, and how to keep remote access running while you patch.

 

## What are CVE-2026-83548 and CVE-2026-83549?

SonicWall disclosed two flaws in the SMA1000 (Secure Mobile Access) line:

1. **CVE-2026-83548** — a pre-authentication server-side request forgery (SSRF) in the Appliance Work Place interface. It carries a **CVSS score of 10.0**, the maximum severity, and lets a remote, unauthenticated attacker reach sensitive functionality and perform unauthorized operations.
2. **CVE-2026-83549** — an OS command injection flaw in the Appliance Management Console, **CVSS 7.8**, which under specific conditions lets an attacker with admin privileges run commands on the appliance.

Security researchers and vendor reporting note the two can be **chained for unauthenticated remote code execution** on unpatched appliances: the pre-auth SSRF opens the door, the command injection runs code, and the result is RCE on the box that carries your remote workforce. SonicWall has confirmed the flaws are under active attack.

 

## Who is affected by this SonicWall SMA1000 vulnerability?

The vulnerabilities affect **SMA1000 models 6210, 7210, and 8200v**, on firmware versions 12.4.3-03453 / 12.5.0-02835 (platform-hotfix) and older.

| Product | Affected versions | Fixed versions |
| --- | --- | --- |
| SMA1000 6210, 7210, 8200v | 12.4.3-03453 / 12.5.0-02835 (platform-hotfix) and older | 12.4.3-03526 / 12.5.0-02952 (platform-hotfix) or higher |
| SMA 100 Series | Not affected, per current SonicWall guidance |  |
| SSL-VPN on SonicWall firewalls | Not affected, per current SonicWall guidance |  |

If you run an SMA1000 6210, 7210, or 8200v as your remote-access gateway, treat this as urgent.

![Summary: two SonicWall SMA1000 flaws chain into remote code execution on an opened appliance, while a separate backup access gateway keeps a laptop connected](https://blog.openvpn.net/hs-fs/hubfs/blog-images/sonicwall-sma1000-cve-2026-83548-83549-summary.png?width=760&name=sonicwall-sma1000-cve-2026-83548-83549-summary.png)

## What should SonicWall SMA1000 admins do now?

1. **Patch immediately.** SonicWall urges customers to upgrade to **12.4.3-03526 / 12.5.0-02952 (platform-hotfix) or higher**. Because exploitation is already happening, this is a same-day action, not a maintenance-window item.
2. **Confirm your build.** Check the exact platform-hotfix version — the affected/fixed boundary is narrow.
3. **Review logs for signs of access** on the management console and Appliance Work Place interface, and follow SonicWall's advisory for any published indicators of compromise.
4. **Verify your fallback access path** before you take the appliance down to patch.

## Why a second, independent remote-access path matters

This is the SMA1000 line's third reported security event in recent months. A maximum-severity, actively exploited flaw in the box that carries your remote workforce is exactly the scenario that argues for not depending on a single vendor's appliance for access — the same pattern we've seen with [Citrix NetScaler](https://blog.openvpn.net/netscaler-zero-days-pentagon-breach-387.5m-bitget-heist), [Fortinet](https://blog.openvpn.net/gunra-ransomware-fortinet-cve-2024-55591-cve-2025-24472), and [Cisco ISE](https://blog.openvpn.net/cve-2026-76460-cisco-ise-zero-day).

A pure VPN/ZTNA layer that runs independently of your primary appliance gives you a disaster-recovery path: when the appliance has to come offline for an emergency patch, people can still reach what they need. [OpenVPN Access Server](https://openvpn.net/access-server/) is a self-hosted, vendor-diverse option that appliance shops deploy as that second, independent access layer — no forklift, no bet on one vendor's patch cadence. The point is not to replace your firewall; it's to make sure a single appliance CVE doesn't take remote access down with it.

### Ready to see how OpenVPN can help protect your organization from attacks?

Try the self-hosted Access Server solution or managed CloudConnexa ZTNA-as-a-service for free — no credit card required.

[See Which One is Right For You](https://openvpn.net/product-comparison/)

 

## FAQ: CVE-2026-83548 and CVE-2026-83549

### Is CVE-2026-83548 being actively exploited?

Yes. SonicWall has confirmed both CVE-2026-83548 and CVE-2026-83549 are being exploited in the wild on SMA1000 appliances.

### How severe is the SonicWall SMA1000 vulnerability?

CVE-2026-83548 is rated CVSS 10.0 (maximum). CVE-2026-83549 is rated CVSS 7.8. Chained, they can enable unauthenticated remote code execution.

### Which SonicWall products are affected?

SMA1000 models 6210, 7210, and 8200v on firmware 12.4.3-03453 / 12.5.0-02835 and older. Current reporting states the SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected.

### What is the fix for CVE-2026-83548 and CVE-2026-83549?

Upgrade to SonicWall SMA1000 firmware 12.4.3-03526 / 12.5.0-02952 (platform-hotfix) or higher.

### How do I keep remote access running while I patch?

Maintain a second, independent remote-access path — a self-hosted VPN/ZTNA layer such as OpenVPN Access Server — so users stay connected while the primary appliance is offline for patching.

![Adam Bullock](https://blog.openvpn.net/hs-fs/hubfs/adamheadshot.jpg?width=300&height=300&name=adamheadshot.jpg)

[Adam Bullock](https://blog.openvpn.net/author/adam-bullock)

Adam has loved tech since the days of the dial-up modem. Read his perspective on the OpenVPN blog.

## Related posts from OpenVPN

### Subscribe for Blog Updates

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Adam Bullock",
    "url" : "https://blog.openvpn.net/author/adam-bullock"
  },
  "dateModified" : "2026-10-08T17:49:00.103Z",
  "datePublished" : "2026-10-08T17:49:00.000Z",
  "headline" : "SonicWall SMA1000 Zero-Days CVE-2026-83548 & CVE-2026-83549 Under Active Exploitation",
  "image" : [ "https://blog.openvpn.net/hubfs/blog-images/sonicwall-sma1000-cve-2026-83548-83549-header.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.openvpn.net/sonicwall-sma1000-cve-2026-83548-83549",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.openvpn.net/hubfs/Dark=True%20Medium.png"
    },
    "name" : "OpenVPN"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. SonicWall has confirmed both CVE-2026-83548 and CVE-2026-83549 are being exploited in the wild on SMA1000 appliances."
    },
    "name" : "Is CVE-2026-83548 being actively exploited?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "CVE-2026-83548 is rated CVSS 10.0 (maximum). CVE-2026-83549 is rated CVSS 7.8. Chained, they can enable unauthenticated remote code execution."
    },
    "name" : "How severe is the SonicWall SMA1000 vulnerability?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "SMA1000 models 6210, 7210, and 8200v on firmware 12.4.3-03453 / 12.5.0-02835 and older. Current reporting states the SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected."
    },
    "name" : "Which SonicWall products are affected?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Upgrade to SonicWall SMA1000 firmware 12.4.3-03526 / 12.5.0-02952 (platform-hotfix) or higher."
    },
    "name" : "What is the fix for CVE-2026-83548 and CVE-2026-83549?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Maintain a second, independent remote-access path — a self-hosted VPN/ZTNA layer such as OpenVPN Access Server — so users stay connected while the primary appliance is offline for patching."
    },
    "name" : "How do I keep remote access running while I patch?"
  } ]
}
```