CVE-2026-83548
Summary
CVE-2026-83548 is a maximum-severity SonicWall SMA1000 zero-day: an SSRF-derived command-injection flaw in the SMA1000 Appliance WorkPlace interface. It is actively chained with CVE-2026-83549 in remote code execution attacks.
Details
SonicWall warned that threat actors are actively chaining two newly disclosed SMA1000 zero-day vulnerabilities in RCE attacks: CVE-2026-83548, a maximum-severity SSRF-derived command-injection flaw in the SMA1000 Appliance WorkPlace interface, and CVE-2026-83549, a command-injection flaw in the Appliance Management Console exploitable by an admin user to execute arbitrary OS commands. The flaws affect SMA1000 6210, 7210 and 8200v models but not SSL-VPN on firewalls or the SMA 100 series. Shadowserver tracks over 400 internet-exposed SMA1000 appliances.
Remediation
SonicWall urged customers to upgrade to the SMA1000 hotfix, re-image appliances and reset credentials/TOTP where indicators of compromise are found. Given the prior CVE-2026-15409/15410 chain is already being abused by ransomware gangs, this product line is a high-priority exposure to remediate.