SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wild — Threadlinqs Intelligence
As of 2026-09-03, SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wild is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-2307 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
A pre-authentication SSRF in the SonicWall SMA1000 Appliance Work Place interface (CVE-2026-83548, CVSS 10.0) can be chained with a post-authentication OS command injection in the Appliance Management
On September 1, 2026, SonicWall PSIRT published advisory SNWLID-2026-0016 disclosing two vulnerabilities affecting the SMA1000 series of Secure Mobile Access SSL-VPN appliances (hardware models 6210 and 7210, and the 8200v virtual appliance). CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF, CWE-918/CWE-441 'confused deputy') in the Appliance Work Place interface, arising from an unintended alternate access path that lets a remote, unauthenticated attacker reach internal appliance functionality that should be restricted. CVE-2026-83549 is a post-authentication OS command injection (CWE-78) in the Appliance Management Console (AMC) that, on its own, requires administrator credentials to run arbitrary operating-system commands. Multiple outlets (Rapid7, BleepingComputer) report that the two flaws are being chained: the unauthenticated SSRF is used to reach the AMC's command-injection surface, letting an attacker execute arbitrary OS commands and achieve remote code execution without any prior authentication. SonicWall's own researchers, William Perry and Adam Babis, are credited with the discovery, and the vendor confirmed active exploitation in the wild at time of disclosure.
CISA added both CVEs to the Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026, with a September 5, 2026 remediation deadline for federal civilian agencies under Binding Operational Directive 26-04. As of publication, no public proof-of-concept, detailed post-exploitation chain, or indicators of compromise have been released by SonicWall, Rapid7, or Sophos; all three explicitly note the absence of published IOCs and attribution. Truesec's detection guidance is the most concrete technical signal available: reviewing appliance logs for POST requests to the /workplace/ endpoint containing URL-encoded internal or loopback addresses (e.g. 127.0.0.1), and for AMC access originating from the appliance's own internal workplace process rather than an approved administrator management station, both indicative of the SSRF-to-AMC chain in action.
The affected models are patched in 12.4.3-03526 platform-hotfix and 12.5.0-02952 platform-hotfix (and later). SMA 100 series appliances and SSL-VPN on SonicWall firewalls are explicitly NOT affected. SonicWall's standard post-compromise guidance is unusually aggressive for an appliance vendor: re-image hardware or redeploy virtual instances from a known-good image, reset all user and administrator passwords, and reinitialize TOTP/MFA seed tokens — mirroring the remediation SonicWall issued after the immediately preceding SMA1000 zero-day pair (CVE-2026-15409/CVE-2026-15410, disclosed July 14, 2026), where Rapid7 documented attackers systematically extracting credentials, session databases, and TOTP seed configurations from compromised appliances after pre-disclosure exploitation traced back to June 22, 2026 by threat actor UTA0533. This is the third SMA1000 zero-day event in roughly 14 months (following a suspected zero-day OS command injection flaw patched around January 2025, CVE-2025-40602 in December 2025, and the July 2026 CVE-2026-15409/15410 pair that CISA later confirmed was exploited by ransomware-affiliated actors), reinforcing NHS England National CSOC's assessment that further exploitation of internet-facing SSL-VPN gateways in this product line is 'almost certain.'
Weaknesses (CWE)
CWE-918, CWE-441, CWE-78
Target sectors: government administration, enterprise, critical infrastructure
Target regions: Global
Timeline
- Approximate date (per The Register's historical review): an earlier suspected zero-day OS command injection flaw in the SMA1000 line was patched, the first in the recent recurring pattern of SMA1000 zero-days.
- Approximate date (per The Register): CISA confirmed ransomware-affiliated actors had exploited an earlier SMA1000 zero-day, foreshadowing the product line's attractiveness to financially motivated intrusion actors.
- Approximate date (per BleepingComputer's historical context): a state-sponsored breach was linked to SonicWall SMA appliance compromise.
- Approximate date (per BleepingComputer): SonicWall issued a zero-day warning for CVE-2025-40602 affecting the SMA product line.
- Volexity traced pre-disclosure zero-day exploitation of the (separate) SMA1000 vulnerability pair CVE-2026-15409/CVE-2026-15410 back to this date, attributed to threat actor UTA0533.
- SonicWall publicly disclosed CVE-2026-15409 (CVSS 10.0 pre-auth SSRF in the Workplace interface) and CVE-2026-15410, the immediately preceding SMA1000 zero-day pair chained for admin access.
- Rapid7 published an Exploit Timeline Report documenting attackers chaining CVE-2026-15409/15410 to extract credentials, active session databases, and TOTP MFA seed configurations from compromised SMA1000 appliances.
- Approximate date (per BleepingComputer): CISA confirmed ransomware-affiliated exploitation tied to the July 2026 SMA1000 vulnerabilities (CVE-2026-15409/15410).
- SonicWall researchers William Perry and Adam Babis discovered and the vendor disclosed CVE-2026-83548 (pre-auth SSRF, CVSS 10.0) and CVE-2026-83549 (post-auth OS command injection, CVSS 7.8) via advisory SNWLID-2026-0016, confirming active exploitation in the wild at time of disclosure.
- CISA added both CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities catalog, setting a September 5, 2026 remediation deadline for federal civilian agencies under BOD 26-04.
- Rapid7 published an Exploit Timeline Report on the chained SSRF-to-command-injection exploitation and announced forthcoming detection content for InsightVM, Nexpose, and Exposure Command.
- Sophos (SophosLabs) published a technical analysis and stated it is monitoring for exploitation activity, with detections planned as available.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-83548, CVE-2026-83549, T1595.002, T1588.006, T1190, T1059, T1078, T1555, T1111, T1005