endoflife.ai
End of Support EOS Edge Device List EOL Checker EOL Watch

SonicWall SMA 1000 Under Active Attack: A CVSS 10.0 SSRF, a Federal Deadline of September 5, and the Sixth KEV Entry Since January 2025

By Scott Bissett  ·  Published: September 3, 2026  ·  EOL Watch — news analysis  ·  Verified against SonicWall advisory SNWLID-2026-0016 (read September 3, 2026), CISA's KEV catalog and SonicWall's Product Life Cycle Tables

SonicWall's enterprise remote-access appliance has two new holes, attackers are already using them, and the federal clock runs out on Friday. Advisory SNWLID-2026-0016 discloses CVE-2026-83548, a pre-authentication server-side request forgery in the SMA 1000 Work Place interface reached through an unintended forward-proxy path, scored CVSS 10.0, and CVE-2026-83549, a post-authentication OS command injection in the Appliance Management Console, scored 7.8. SonicWall's own words: its PSIRT “has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory.” There is no workaround.

CISA added both to the Known Exploited Vulnerabilities catalog on September 2, 2026 with a due date of September 5, 2026, the three-day window it reserves for the most urgent entries and has used routinely this year. They are the fifth and sixth SMA 1000 entries in the catalog since January 2025.

What is affected, and what is fixed

AffectedFixed
ModelsSMA 1000 6210, 7210, 8200vsame models
12.4.3 train12.4.3-03453 (platform-hotfix) and older12.4.3-03526 (platform-hotfix) and higher
12.5.0 train12.5.0-02835 (platform-hotfix) and older12.5.0-02952 (platform-hotfix) and higher
Not affectedSSL-VPN on SonicWall firewalls; the SMA 100 series (per the advisory)

The hotfixes are on mysonicwall.com. SonicWall's recommended actions go beyond patching: upgrade, then have SonicWall support review the appliance for indicators of compromise, and if any are found, re-image a physical appliance or re-deploy a virtual one, change every user and administrator password, and reset TOTP tokens. That last set of steps is the tell that the vendor is treating this as a compromise-response event, not a patch cycle. The flaws were found internally, by William Perry and Adam Babis of SonicWall.

The wording guard. SonicWall scopes the affected products to the 6210, 7210 and 8200v and does not list the SMA 6200 or 7200. The defensible statement is that the hotfix is built for the in-support models. Whether the same code paths exist on the SMA 6200, past End of Support since August 1, 2024, or the SMA 7200, past it since August 1, 2025, is not something the vendor has said, and we do not say it either. What is certain is that neither of those two receives firmware from SonicWall for anything.

Six entries in twenty months

The SMA 1000 is a small product line with a KEV record that now rivals much larger ones. Every entry below was confirmed exploited by CISA; the two 2025 entries carried the required action to apply mitigations or discontinue use of the product.

CVEAdded to KEVFederal dueWhat it was
CVE-2026-83548Sep 2, 2026Sep 5, 2026Pre-auth SSRF via unintended forward proxy in Work Place (CVSS 10.0)
CVE-2026-83549Sep 2, 2026Sep 5, 2026Post-auth OS command injection in the Appliance Management Console (CVSS 7.8)
CVE-2026-15409Jul 14, 2026Jul 17, 2026Server-side request forgery (advisory SNWLID-2026-0008)
CVE-2026-15410Jul 14, 2026Jul 17, 2026Code injection (advisory SNWLID-2026-0008)
CVE-2025-40602Dec 17, 2025Dec 24, 2025Missing authorization
CVE-2025-23006Jan 24, 2025Feb 14, 2025Deserialization of untrusted data in the Appliance Management Console

Two SSRF entries eight weeks apart, both reachable before authentication, is the pattern to notice: the July pair was fixed by hotfix, and the September pair is the same class of flaw on the same interface. An SMA 1000 that missed the July hotfix window was exposed twice; one that installs the September hotfix and does not check for indicators of compromise may be patched and owned at the same time, which is exactly why the vendor's guidance includes the password and TOTP reset.

Where the line stands

Per SonicWall's Product Life Cycle Tables, tracked on our SMA 1000 page: the SMA 6210 and 7210 are current, with no last order day or end-of-support date published, and the 8200v is the virtual appliance. The SMA 6200 reached End of Support on August 1, 2024 and the SMA 7200 on August 1, 2025. A 6200 or 7200 still terminating remote access today is an end-of-support edge device in the sense of CISA's Binding Operational Directive 26-02, on a product line that has just produced its sixth exploited vulnerability in twenty months; the directive's answer for that combination is retirement, not a hotfix that does not exist.

What to do by Friday

If you run a 6210, 7210 or 8200v: install 12.4.3-03526 or 12.5.0-02952 (or higher) now; open a case with SonicWall support for the indicator-of-compromise review the advisory calls for; and if anything is found, re-image or re-deploy, rotate every credential the appliance holds, and reset TOTP. Do the credential step even on a clean review if the appliance was internet-facing on an affected build for any length of time since the July advisory.

If you run a 6200 or 7200: there is no hotfix to install and there will not be one. Replace the appliance, and until it is replaced, take the Work Place interface off the internet. If you run the SMA 100 series: this advisory does not apply, but that line has its own KEV record and its own end-of-support dates worth checking.

Facing an end-of-life deadline?
Tell us which product and we’ll reply with vetted extended-support options and pricing guidance — free, no obligation. Vendors don’t pay for placement.

Free · No obligation · Independent · dates verified against vendor sources · Not urgent? Follow the EOL radar or see the 2026 EOL calendar →

Frequently Asked Questions

Which SonicWall SMA 1000 versions are affected by CVE-2026-83548 and CVE-2026-83549?

Per SonicWall advisory SNWLID-2026-0016: SMA 1000 models 6210, 7210 and 8200v running 12.4.3-03453 (platform-hotfix) and older, or 12.5.0-02835 (platform-hotfix) and older. Fixed builds are 12.4.3-03526 and 12.5.0-02952 and higher. SonicWall states the vulnerabilities do not affect SSL-VPN on SonicWall firewalls or the SMA 100 series.

Is the SMA 1000 vulnerability being exploited?

Yes. SonicWall's advisory states that its PSIRT investigated a case indicating active exploitation of the vulnerabilities, and CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 2, 2026 with a federal due date of September 5, 2026.

Is there a workaround?

No. SonicWall lists no workaround. Its recommended actions are to upgrade to the latest platform-hotfix, contact SonicWall support to review the appliance for indicators of compromise, and if any are found, re-image or re-deploy the appliance, change all user and administrator passwords, and reset TOTP tokens.

Are the older SMA 6200 and SMA 7200 affected?

SonicWall does not list them. The advisory scopes the affected products to the 6210, 7210 and 8200v, and the hotfixes are built for those models. The SMA 6200 reached End of Support on August 1, 2024 and the SMA 7200 on August 1, 2025, so neither receives firmware in any case; whether the same code paths exist on them is not something the vendor has stated.

How many SMA 1000 vulnerabilities are in CISA's KEV catalog?

Six since January 2025: CVE-2025-23006 (added January 24, 2025), CVE-2025-40602 (December 17, 2025), CVE-2026-15409 and CVE-2026-15410 (July 14, 2026), and CVE-2026-83548 and CVE-2026-83549 (September 2, 2026).

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)