Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

SonicWall disclosed on September 1, 2026 that two vulnerabilities in its SMA 1000 series secure remote access appliances are being actively exploited in the wild, according to the vendor’s own advisory, SNWLID-2026-0016, and confirmed by CISA, Rapid7 and Qualys Threat Protect.

A Chainable Path to Unauthenticated RCE

The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA 1000 Appliance Work Place interface, carrying the maximum possible CVSS score of 10.0. According to SonicWall’s advisory, an unintended alternate access path causes the appliance to act as an unintended forward proxy, letting a remote unauthenticated attacker reach sensitive functionality. Rapid7’s analysis found that this SSRF flaw can be chained with a second, high-severity OS command injection vulnerability in the Appliance Management Console, CVE-2026-83549, which normally requires authenticated administrator access, to achieve full unauthenticated remote code execution.

Federal Deadline and Wide Exposure

CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 5, 2026 remediation deadline for federal civilian agencies. SonicWall SMA 1000 appliances are widely deployed as VPN and zero-trust access gateways by large enterprises, government agencies and managed service providers, making the appliance an attractive target given the level of internal network access it typically brokers.

Response

SonicWall has released a hotfix addressing CVE-2026-83548; the company states no workaround is available for organizations that cannot immediately patch. Security researchers recommend organizations apply the hotfix without delay, review SMA 1000 logs for signs of the unauthorized proxy behavior described in the advisory, and treat any indicators of compromise found before the patch was applied as a potential breach requiring further investigation.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *