[CIVN-2026-0437] Multiple Vulnerabilities in Sonicwall SMA1000

By Published On: September 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Sonicwall SMA1000


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Systems Affected


SMA1000 Models ¿ 6210, 7210 and 8200v (all hypervisors)

Software Affected


12.4.3-03453 (platform-hotfix) and earlier versions

12.5.0-02835 (platform-hotfix) and earlier versions

Overview


Multiple vulnerabilities have been reported in SonicWall Secure Mobile Access (SMA) 1000 Series appliances, which could allow a remote unauthenticated attacker to perform Server-Side Request Forgery (SSRF) or a remote authenticated administrator to execute arbitrary operating system commands.


Target Audience:

All end-user organizations and individuals using SonicWall Secure Mobile Access (SMA) 1000 Series appliances.


Risk Assessment:

Risk of arbitrary operating system command execution, Server-Side Request Forgery (SSRF), Remote Code Execution (RCE), and compromise of affected systems.


Impact Assessment:

Potential for unauthorized access to sensitive functionality, unauthorized requests to internal or unintended locations, arbitrary operating system command execution, Remote Code Execution, and compromise of affected appliances.


Description


SonicWall Secure Mobile Access (SMA) 1000 Series appliances are secure remote access solutions used to provide secure access to enterprise networks and applications.


Multiple vulnerabilities have been identified in SonicWall Secure Mobile Access (SMA) 1000 Series appliances. These vulnerabilities include a pre-authentication Server-Side Request Forgery (SSRF) vulnerability and a post-authentication OS Command Injection vulnerability.


Successful exploitation of these vulnerabilities could allow an attacker to access internal or unintended network locations, execute arbitrary operating system commands and compromise the affected appliance.


Note – These vulnerabilities are being actively exploited in the wild.


Solution


Apply appropriate security updates and mitigations as recommended by the vendor.

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016



Vendor Information


SonicWall

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016


References


 

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016


CVE Name

CVE-2026-83548

CVE-2026-83549




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZi8YACgkQ3jCgcSdc

ys/AxBAAhtkuMBC/qA/WxVMe0hYKa0IEeAyXqFdauI4fdbm4FhYUtTZ7VIALdlNm

SH9ikXKWvrg+1nj+G4NWUa76vgQNPhkkjcoHy9lJyTMXLzwrV9/ldKILFK8IKnpB

piHYbr6YZvsGd3k1LKTBmwJQPY7MzkcMuVrnUwSCwgNMtpZgJBzWtSUlqLEWImKj

rExQD2bhPiG++jjso+wcYtr5tnClBuxBDsa/Zlu4euk7Xdnv2Zh8NY6dw6SNH6Is

Mvtnyul0AA3J6hx87uFNw07jzMR0h2USUQQxc002A2P9PiYxmEc0P6w0CpoqBstw

RWxZhj2saWzWOeufxCRHKUskmWTOSLh8U1y5UpdjGg9Pn8ywmR/5oziAhUKtgX1S

t2gRLyMxQ+piggjcEfQq4IanmGl3H/5tKDYwJe0vRd/gFx1XX636FWrTbw5TJrch

1Xs4kENLKI2xBc9FaZ+7kd0b9eh0L3MaM4d17DYthwDpn0phG3ApZMohqfG4xuKw

41g/d3dwcPWxj2I/MBmhnUukC0NnwApatrgGr9l+fdUQ5p47pwntPhRSW3h/gVEM

MlnGAEK35fwGW4UAtxEXgVuWQva0N2OFQKRjlZjRy1cxADHFh4yt8PQUM/rrj4TE

3r4ZFKLW7OSgyHCkzNkIo+Hbadp1glSzfQAxTPMa/JBxtplO3f8=

=+tTz

—–END PGP SIGNATURE—–

Share this article