Skip to content
September 1, 2026 product notice

September 1, 2026 product notice

www.sonicwall.com September 6, 2026

CVE-2026-83548: Pre-authentication SSRF via unintended forward-proxy - CVSS Score: 10.0 (Critical)

CVE-2026-83549: Post-authentication Remote Code Execution (RCE) Vulnerability – CVSS Score: 7.8 (High)

SonicWall Secure Mobile Access 1000 Series 12.4.3 and 12.5.0 firmware (see impacted versions) are affected by multiple vulnerabilities.

IMPORTANT: These vulnerabilities have been confirmed as being actively exploited in the wild.

These vulnerabilities are unrelated to any other reported vulnerability on other SonicWall products.

Please review the table below to see the products and their versions that are impacted:

Impacted Versions (platform-hotfix)

SMA 1000 (6210, 7210, 8200v - all hypervisors)

12.4.3-03453 (all versions)

12.5.0-02835 (all versions)

Impacted Versions (platform-hotfix)

SMA 1000 (6210, 7210, 8200v - all hypervisors)

12.4.3-03453 (all versions)

12.5.0-02835 (all versions)

All organizations with deployments of SMA1000 appliances (whether virtual or physical) on affected versions must perform the following:

Upgrade to the latest hotfix version – available via

SonicWall Technical Support for assistance reviewing the system for indicators of compromise (IoCs)

If IoCs are detected on the system: Re-image (hardware) or re-deploy (virtual) appliances. Change all user and administrator passwords. Reset TOTP tokens.

Re-image (hardware) or re-deploy (virtual) appliances.

Change all user and administrator passwords.

SonicWall strongly advises Secure Mobile Access customers on affected versions follow the guidance provided.

How to re-image hardware appliances (SMA6210/SMA7210)