CVE-2026-83549 – SonicWall SMA1000

CVSS 7.8 IMPORTANT Zero Day – Immediate Deployment

“Active exploitation combines a pre-authentication access path with post-authentication command execution on exposed SMA1000 appliances.”

SonicWall addresses two actively exploited vulnerabilities in the SMA1000 series. CVE-2026-83548 is a Critical pre-authentication SSRF flaw in the Appliance Work Place interface that can allow an unauthenticated remote attacker to reach sensitive functionality and perform unauthorized operations. The CVSS score is 10.0, which is Critical severity.

CVE-2026-83549 is a High-severity OS command injection flaw in the Appliance Management Console that can allow a remote authenticated administrator to execute arbitrary operating-system commands. The CVSS score is 7.8, which is High severity. Active exploitation is confirmed for both vulnerabilities. Fixed hotfixes include 12.4.3-03526 and 12.5.0-02952.

Key Details

Affected Product
Sonicwall Sma8200v
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-78
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.