The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that these flaws are actively being exploited in real-world attacks.
The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, affect SonicWall’s Secure Mobile Access (SMA1000) remote-access appliances.
CISA Warns SonicWall SMA1000 Flaws
CISA added both vulnerabilities to the KEV Catalog on September 2, 2026, and instructed U.S. federal civilian agencies to implement vendor-recommended mitigations by September 5, 2026.
The agency has also marked both entries as requiring forensic triage under Binding Operational Directive (BOD) 26-04, indicating that organizations should assess whether any exposed devices may have already been compromised.
CVE-2026-83548: This vulnerability is a server-side request forgery (SSRF) issue related to CWE-918 and CWE-441. A remote, unauthenticated attacker could exploit this flaw to access sensitive functionalities and perform unauthorized operations.
SSRF vulnerabilities are particularly concerning in internet-facing appliances, as they can allow the affected system to send attacker-controlled requests to internal services typically unreachable from the public internet.
In a remote-access environment, this behavior could expose administrative functions, cloud metadata endpoints, or internal network resources.
CVE-2026-83549: This is an OS command injection vulnerability associated with CWE-78. According to CISA, a remote attacker authenticated as an administrator could execute arbitrary operating system commands, leading to remote code execution (RCE).
An attacker with valid or stolen administrative credentials could utilize command injection to run commands directly on the appliance, establish persistent access, collect configuration data, or pivot into connected enterprise environments.
The combination of an unauthenticated SSRF vulnerability and an authenticated command-injection weakness poses a significant threat to defenders managing externally accessible SMA1000 deployments.
While CISA has not listed either vulnerability as involved in ransomware campaigns, active exploitation and the need for forensic triage mean that security teams should prioritize exposed SonicWall SMA1000 appliances as a critical incident-response concern.
Organizations should take the following actions:
- Apply SonicWall’s available security updates and mitigations immediately.
- Identify all internet-exposed SMA1000 appliances and verify their patch status.
- Review administrator accounts, authentication logs, and recent configuration changes.
- Hunt for unusual outbound connections, unexpected processes, and suspicious command execution.
- Rotate privileged credentials if compromise is suspected.
- Isolate or discontinue use of vulnerable appliances when mitigations cannot be applied.
Federal agencies must meet CISA’s September 5 remediation deadline, while private-sector organizations should also act swiftly, as inclusion in the KEV Catalog indicates that attackers have already demonstrated the capability to exploit these vulnerabilities.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.





