# SonicWall SMA1000 flaws exploited in wild

Published: 2026-09-02 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/06b5dfd5-022a-513a-8dd8-bd1178f639f1/sonicwall-sma1000-flaws-exploited-in-wild

> CERT-FR warns two actively exploited SonicWall SMA1000 vulnerabilities allow remote code execution and SSRF.

CERT-FR has issued an advisory covering multiple vulnerabilities in SonicWall SMA1000 series appliances (models 6210, 7210, and 8200v). The flaws enable remote arbitrary code execution and server-side request forgery (SSRF). Affected versions include 12.5.x builds prior to 12.5.0-02952 and versions prior to 12.4.3-03526.

SonicWall's own security bulletin (SNWLID-2026-0016) confirms that CVE-2026-83548 and CVE-2026-83549 are being actively exploited in the wild, elevating the urgency for administrators managing affected Secure Mobile Access appliances. CERT-FR directs organizations to SonicWall's advisory for patch information.

Given the active exploitation status and the remote code execution impact on internet-facing secure remote access infrastructure, affected organizations should prioritize patching to the fixed versions immediately and review SMA1000 access logs for signs of compromise.

## Mentioned in this report

- Vulnerabilities: CVE-2026-83548 (KEV), CVE-2026-83549 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1103

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/06b5dfd5-022a-513a-8dd8-bd1178f639f1/sonicwall-sma1000-flaws-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
