SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances.
The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands.
The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident Response Team investigated a case indicating active exploitation.
SonicWall urged organizations to install the available platform hotfixes immediately and review exposed systems for signs of compromise.
The vulnerabilities affect SMA1000 6210, 7210, and 8200v appliances running version 12.4.3-03453 or earlier, as well as version 12.5.0-02835 or earlier. SonicWall stated that SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected.
SonicWall RCE Vulnerabilities Exploited
The most severe issue is tracked as CVE-2026-83548 and carries a CVSS score of 10.0. It is a pre-authentication server-side request forgery vulnerability in the SMA1000 Appliance Workplace interface.
According to SonicWall, the flaw stems from an unintended alternate access path that can serve as a forward proxy. A remote, unauthenticated attacker could exploit this path to access sensitive internal functionality and perform unauthorized operations.
The vulnerability is associated with CWE-918, covering server-side request forgery, and CWE-441, which describes an unintended proxy or confused-deputy condition.
SSRF vulnerabilities are especially dangerous in remote-access appliances because they can allow attackers to make requests from the device itself, potentially bypassing network restrictions designed to protect internal services.
SonicWall also addressed CVE-2026-83549, a post-authentication remote code execution flaw in the SMA1000 Appliance Management Console.
The vulnerability has a CVSS score of 7.8 and stems from improper neutralization of special characters in operating system commands.
An authenticated attacker with administrator privileges could exploit the command injection issue to execute arbitrary commands on the appliance operating system.
While this vulnerability requires valid administrator access, it could be especially damaging when chained with another weakness that provides unauthorized access to appliance functions.
Remote-access infrastructure remains a high-value target because it often sits at the edge of enterprise networks and handles user authentication, VPN connectivity, and access to internal resources.
A compromised SMA appliance may provide attackers with a foothold for credential theft, lateral movement, and further network intrusion.
There is no workaround for either issue. Organizations should upgrade SMA1000 appliances to version 12.4.3-03526 or later, or to version 12.5.0-02952 or later, depending on the software branch they have deployed.
SonicWall also recommends contacting technical support to review appliances for indicators of compromise. If compromise indicators are found, organizations should re-image affected physical appliances or redeploy affected virtual appliances.
Administrators should then change all user and administrator passwords and reset TOTP tokens to invalidate potentially stolen authentication factors.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

