
SonicWall's SMA1000 Just Had Its Third Zero-Day SSRF Pair in Nine Months
CVE-2026-83548 and CVE-2026-83549 were exploited before SonicWall even disclosed them. The federal patch deadline is tomorrow — and this is the third time this exact shape of bug has hit the same appliance.
CVE Tools4 min read
On September 1, 2026, SonicWall published advisory SNWLID-2026-0016, disclosing two vulnerabilities in its SMA1000 series secure remote access appliances — and confirming, in the same breath, that it had already found both being exploited in the wild. CISA added both to its Known Exploited Vulnerabilities catalog the next day. The remediation deadline for federal agencies: September 5, 2026 — one day from now.
Scores as of 2026-09-04live record →
How the two bugs chain
CVE-2026-83548 lives in the SMA1000's public-facing Work Place interface. SonicWall's own description calls it access via "an unintended alternate access path" — the interface can be abused as an unintended proxy, a confused-deputy pattern (CWE-441/CWE-918), by anyone on the network with zero credentials. On its own that's already a CVSS 10.0.
CVE-2026-83549 sits deeper: OS command injection (CWE-78) in the Appliance Management Console (AMC), the admin-only control plane. Standalone, it needs an authenticated administrator session — which is why NVD scored it a comparatively modest 7.8. Chained together, the SSRF supplies the access the command-injection bug otherwise requires, and the pair collapses into unauthenticated remote code execution on an internet-facing appliance.
CVE-2026-83548 + CVE-2026-83549 attack chain
- Unauthenticated attacker
- CVE-2026-83548 Work Place SSRF
- Appliance acts as unintended proxy into AMC
- CVE-2026-83549 OS command injection
- Unauthenticated RCE on the appliance
This is the third time, not the first
SMA1000 has now produced three separate zero-day incidents inside nine months, each a variation on the same theme: a way into the appliance's control surface without full credentials.
| Date | CVE(s) | CVSS | Flaw class | Outcome |
|---|---|---|---|---|
| Dec 18, 2025 | CVE-2025-40602 | 6.6 | Local privilege escalation in the AMC | Not confirmed exploited |
| Jul 14, 2026 | CVE-2026-15409 + CVE-2026-15410 | 10.0 chained to root | Pre-auth SSRF + second bug for root | Exploited as a zero-day, KEV-listed |
| Sep 1, 2026 | CVE-2026-83548 + CVE-2026-83549 | 10.0 chained to RCE | Pre-auth SSRF + AMC command injection | Exploited as a zero-day, KEV-listed |
Mitigation guidance
- Upgrade SMA1000 to platform-hotfix 12.4.3-03526 or 12.5.0-02952 (or later) immediately — this is the fix for both CVEs.
- Treat any internet-facing SMA1000 as potentially already compromised: SonicWall confirmed exploitation predated disclosure.
- Contact SonicWall support to review the appliance for indicators of compromise before assuming a clean patch closes the incident.
- If compromise is confirmed, SonicWall's own guidance is to re-image physical appliances or redeploy virtual ones, then rotate all credentials and reset TOTP/MFA seeds — a stolen seed survives a patch.
Same day, unrelated products
CISA's September 2 KEV batch wasn't SonicWall-only. It also added CVE-2026-82329 (JFrog Artifactory authentication bypass, CVSS 9.8), CVE-2026-49869 (Kestra OSS unauthenticated RCE via an auth-filter suffix-match bug, CVSS 10.0), and CVE-2026-59822 (LiteLLM's MCP OAuth2-passthrough auth bypass, CVSS 8.2) — three unrelated products, same alert. Worth knowing if you triage KEV additions by date rather than by vendor: not everything that lands together is connected.
CVSS/EPSS/KEV data as of 2026-09-04