A remote-access gateway is only as trustworthy as its own front door. SonicWall just confirmed that two bugs in its SMA1000 series let an attacker walk through that door without a password.
One bug gets you in, the other gets you root
CVE-2026-83548, rated a maximum CVSS 10.0, is a pre-authentication server-side request forgery in the SMA1000’s Work Place portal, the interface remote users hit first when connecting. On its own, it lets an unauthenticated attacker make the appliance issue requests on their behalf.
CVE-2026-83549, rated 7.8, is an OS command injection in the Appliance Management Console. Normally that would require admin credentials to reach, which is why it is rated lower on its own. Chained with the SSRF, though, an attacker never needs those credentials in the first place: the first bug gets them to the console, the second gets them a shell.
The affected models are the SMA1000 series 6210, 7210 and 8200v, the appliances organisations deploy specifically to give staff secure remote access to internal networks. SonicWall shipped hotfixes 12.4.3-03526 and 12.5.0-02952 on September 1, the same day it disclosed both bugs.
CISA gave this a Friday deadline
CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, confirming active exploitation, and set a remediation deadline of September 5 for US federal agencies. A same-week KEV deadline is CISA’s way of saying attackers are not waiting, and a gateway product built to sit on the public internet is exactly the kind of asset that gets swept up in opportunistic scanning within days of a KEV listing, regardless of which country runs it.
What to do now
If your organisation runs an SMA1000 appliance, confirm you are on 12.4.3-03526, 12.5.0-02952 or later today, and check your logs for Work Place portal requests that do not match normal remote-access patterns. A VPN gateway compromised at the appliance level bypasses every access control behind it, which makes this worth treating as urgent rather than routine patching.
If you would like a second set of eyes on your remote-access infrastructure, contact Excello Digital. We help European organisations audit exactly the kind of internet-facing gateway that this bug targets, before an attacker finds it first.
