Published: Thu 03 September 2026
Prepared by: Adam Skupien, Vulnerability Security Analyst
SonicWall has disclosed two new vulnerabilities affecting SMA 1000 Series secure remote access appliances -CVE-2026-83548 (Server-Side Request Forgery, CVSSv3.1 10.0) and CVE-2026-83549 (OS Command Injection, CVSSv3.1 7.8) - which SonicWall has confirmed were actively exploited in the wild and which may be chained by an attacker to achieve remote code execution.
This is the second SMA 1000 zero-day chain in as many months (see Triskele Labs' prior bulletin on CVE-2026-15409 and CVE-2026-15410). Organisations that already patched and investigated for compromise following that earlier incident must treat this as a separate incident and a separate investigation window - that remediation does not cover this new exploit chain.
SonicWall discovered this exploitation internally and disclosed it on 2 September 2026 (SNWLID-2026-0016). As of this writing, SonicWall has not published indicators of compromise, exploitation timelines, or detailed technical root-cause information - this bulletin will be updated as more detail becomes available.
CVE-2026-83548 - Server-Side Request Forgery (SSRF)
/wsproxy WebSocket-proxy endpoint, reachable by spoofing client identifiers (User-Agent and URI parameters) to tunnel traffic to internal-only services.CVE-2026-83549 - OS Command Injection
Exposure condition: Applies to internet-facing SMA1000 Appliance WorkPlace interfaces - the standard, intended deployment model for these devices.
| Product | Affected | Fixed |
|---|---|---|
| SMA1000 Models - 6210, 7210, 8200v | 12.4.3-03453 and older 12.5.0-02835 and older |
12.4.3-03526 and later 12.5.0-02952 and later |
The latest platform-hotfix is available for download on mysonicwall.com.
Successful exploitation of this chain could give a remote attacker, beginning with no authentication, a path to command execution on an internet-facing remote access gateway. Given the role SMA1000 appliances play brokering credentials, sessions, and MFA data for remote users, potential impact includes:
Over 400 internet-exposed SMA1000 appliances are currently visible to internet-wide scanning (Shadowserver), some proportion of which may already be patched.
Patch immediately - there is no workaround. SonicWall's advisory confirms active exploitation and states that all organisations with SMA1000 deployments (virtual or physical) on affected versions must:
SonicWall has not published detailed IOCs, log signatures, or a confirmed exploitation timeline for this chain, and directs customers to its Technical Support team for IOC review on a case-by-case basis. Per SonicWall's guidance, if IOCs are detected on a system:
Pending further public technical detail, organisations may also wish to:
/var/log/aventail/extraweb_access.log, /var/log/aventail/access_servers.log, /var/log/aventail/ctrl-service.log) as a starting point, watching in particular for anomalous /wsproxy-style requests.MDR customers: Triskele Labs will develop and tune detections for behaviours consistent with the exploitation of CVE-2026-83548 and CVE-2026-83549 across supported log sources as further technical detail becomes available.
Vulnerability Management customers: Environments will be assessed for exposed and vulnerable SMA1000 appliance versions; any findings will be communicated through priority channels.