SonicWall SMA 1000 Under Active Attack: A CVSS 10.0 SSRF, a Federal Deadline of September 5, and the Sixth KEV Entry Since January 2025
SonicWall's enterprise remote-access appliance has two new holes, attackers are already using them, and the federal clock runs out on Friday. Advisory SNWLID-2026-0016 discloses CVE-2026-83548, a pre-authentication server-side request forgery in the SMA 1000 Work Place interface reached through an unintended forward-proxy path, scored CVSS 10.0, and CVE-2026-83549, a post-authentication OS command injection in the Appliance Management Console, scored 7.8. SonicWall's own words: its PSIRT “has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory.” There is no workaround.
CISA added both to the Known Exploited Vulnerabilities catalog on September 2, 2026 with a due date of September 5, 2026, the three-day window it reserves for the most urgent entries and has used routinely this year. They are the fifth and sixth SMA 1000 entries in the catalog since January 2025.
What is affected, and what is fixed
| Affected | Fixed | |
|---|---|---|
| Models | SMA 1000 6210, 7210, 8200v | same models |
| 12.4.3 train | 12.4.3-03453 (platform-hotfix) and older | 12.4.3-03526 (platform-hotfix) and higher |
| 12.5.0 train | 12.5.0-02835 (platform-hotfix) and older | 12.5.0-02952 (platform-hotfix) and higher |
| Not affected | SSL-VPN on SonicWall firewalls; the SMA 100 series (per the advisory) | |
The hotfixes are on mysonicwall.com. SonicWall's recommended actions go beyond patching: upgrade, then have SonicWall support review the appliance for indicators of compromise, and if any are found, re-image a physical appliance or re-deploy a virtual one, change every user and administrator password, and reset TOTP tokens. That last set of steps is the tell that the vendor is treating this as a compromise-response event, not a patch cycle. The flaws were found internally, by William Perry and Adam Babis of SonicWall.
Six entries in twenty months
The SMA 1000 is a small product line with a KEV record that now rivals much larger ones. Every entry below was confirmed exploited by CISA; the two 2025 entries carried the required action to apply mitigations or discontinue use of the product.
| CVE | Added to KEV | Federal due | What it was |
|---|---|---|---|
| CVE-2026-83548 | Sep 2, 2026 | Sep 5, 2026 | Pre-auth SSRF via unintended forward proxy in Work Place (CVSS 10.0) |
| CVE-2026-83549 | Sep 2, 2026 | Sep 5, 2026 | Post-auth OS command injection in the Appliance Management Console (CVSS 7.8) |
| CVE-2026-15409 | Jul 14, 2026 | Jul 17, 2026 | Server-side request forgery (advisory SNWLID-2026-0008) |
| CVE-2026-15410 | Jul 14, 2026 | Jul 17, 2026 | Code injection (advisory SNWLID-2026-0008) |
| CVE-2025-40602 | Dec 17, 2025 | Dec 24, 2025 | Missing authorization |
| CVE-2025-23006 | Jan 24, 2025 | Feb 14, 2025 | Deserialization of untrusted data in the Appliance Management Console |
Two SSRF entries eight weeks apart, both reachable before authentication, is the pattern to notice: the July pair was fixed by hotfix, and the September pair is the same class of flaw on the same interface. An SMA 1000 that missed the July hotfix window was exposed twice; one that installs the September hotfix and does not check for indicators of compromise may be patched and owned at the same time, which is exactly why the vendor's guidance includes the password and TOTP reset.
Where the line stands
Per SonicWall's Product Life Cycle Tables, tracked on our SMA 1000 page: the SMA 6210 and 7210 are current, with no last order day or end-of-support date published, and the 8200v is the virtual appliance. The SMA 6200 reached End of Support on August 1, 2024 and the SMA 7200 on August 1, 2025. A 6200 or 7200 still terminating remote access today is an end-of-support edge device in the sense of CISA's Binding Operational Directive 26-02, on a product line that has just produced its sixth exploited vulnerability in twenty months; the directive's answer for that combination is retirement, not a hotfix that does not exist.
What to do by Friday
If you run a 6210, 7210 or 8200v: install 12.4.3-03526 or 12.5.0-02952 (or higher) now; open a case with SonicWall support for the indicator-of-compromise review the advisory calls for; and if anything is found, re-image or re-deploy, rotate every credential the appliance holds, and reset TOTP. Do the credential step even on a clean review if the appliance was internet-facing on an affected build for any length of time since the July advisory.
If you run a 6200 or 7200: there is no hotfix to install and there will not be one. Replace the appliance, and until it is replaced, take the Work Place interface off the internet. If you run the SMA 100 series: this advisory does not apply, but that line has its own KEV record and its own end-of-support dates worth checking.
Frequently Asked Questions
Which SonicWall SMA 1000 versions are affected by CVE-2026-83548 and CVE-2026-83549?
Per SonicWall advisory SNWLID-2026-0016: SMA 1000 models 6210, 7210 and 8200v running 12.4.3-03453 (platform-hotfix) and older, or 12.5.0-02835 (platform-hotfix) and older. Fixed builds are 12.4.3-03526 and 12.5.0-02952 and higher. SonicWall states the vulnerabilities do not affect SSL-VPN on SonicWall firewalls or the SMA 100 series.
Is the SMA 1000 vulnerability being exploited?
Yes. SonicWall's advisory states that its PSIRT investigated a case indicating active exploitation of the vulnerabilities, and CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 2, 2026 with a federal due date of September 5, 2026.
Is there a workaround?
No. SonicWall lists no workaround. Its recommended actions are to upgrade to the latest platform-hotfix, contact SonicWall support to review the appliance for indicators of compromise, and if any are found, re-image or re-deploy the appliance, change all user and administrator passwords, and reset TOTP tokens.
Are the older SMA 6200 and SMA 7200 affected?
SonicWall does not list them. The advisory scopes the affected products to the 6210, 7210 and 8200v, and the hotfixes are built for those models. The SMA 6200 reached End of Support on August 1, 2024 and the SMA 7200 on August 1, 2025, so neither receives firmware in any case; whether the same code paths exist on them is not something the vendor has stated.
How many SMA 1000 vulnerabilities are in CISA's KEV catalog?
Six since January 2025: CVE-2025-23006 (added January 24, 2025), CVE-2025-40602 (December 17, 2025), CVE-2026-15409 and CVE-2026-15410 (July 14, 2026), and CVE-2026-83548 and CVE-2026-83549 (September 2, 2026).
Related
- SonicWall SMA 1000 — every model with live status · SMA 100 · SonicOS
- SonicWall's Gen 6 firewall cliff: October 1, 2026 — the other SonicWall deadline this month
- The EOS Edge Device List — 25 platforms, vendor-verified, machine-readable
- Exploited & Unpatchable · End of support & the BOD 26-02 clock