> ## Content Index
> Fetch the complete content index at: https://badtech.org/llms.txt
> Use this file to discover other available public pages before exploring further.

# Active exploitation hits SonicWall SMA1000 vulnerability chain with unauthenticated RCE path
- URL: https://badtech.org/active-exploitation-hits-sonicwall-sma1000-vulnerability-chain-with-unauthenticated-rce-path/
- Published: 2026-09-05T00:50:19.000Z
- Updated: 2026-09-05T00:50:19.000Z
- Author: Adam Field
- Tags: Vulnerabilities

Active exploitation is targeting SonicWall SMA1000 appliances through CVE-2026-83548 and CVE-2026-83549, a pre-authentication SSRF flaw and a post-authentication OS command-injection flaw that can be chained to reach unauthenticated remote code execution. Affected models are SMA 6210, SMA 7210 and SMA 8200v on 12.4.3-03453 or earlier, or 12.5.0-02835 or earlier; fixed builds are 12.4.3-03526 and 12.5.0-02952 or later.

These are SonicWall Secure Mobile Access appliances used for enterprise remote access. SonicWall SMA 100 appliances and SSL-VPN functionality on SonicWall firewalls are outside this advisory’s scope.

For exposed affected systems, the supplied guidance is to identify internet-facing appliances, preserve relevant logs, apply the fixed builds, and investigate for compromise rather than treating patching as sufficient closure. If compromise is confirmed or indicators are found, response guidance includes re-imaging physical appliances or redeploying virtual ones, changing user and administrator passwords, and resetting TOTP tokens.

## Sources

- [Center for Internet Security / MS-ISAC: Multiple Vulnerabilities in SonicWall SMA1000 Series Appliances Could Allow for Remote Code Execution](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-sonicwall-sma1000-series-appliances-could-allow-for-remote-code-execution%5F2026-087?ref=badtech.org)
- [Field Effect: Active exploitation of SonicWall SMA1000 zero-day vulnerabilities](https://fieldeffect.com/blog/active-exploitation-sonicwall-sma1000?ref=badtech.org)
- [IONIX: CVE-2026-83548 – Pre-Auth SSRF (Chained to RCE)](https://www.ionix.io/threat-center/cve-2026-83548?ref=badtech.org)
- [Security.io: SonicWall SMA 1000 zero-days demand compromise checks, not patch-only closure](https://www.security.io/articles/2026/09/03/sonicwall-sma1000-zero-days?ref=badtech.org)
- [Techleet Solutions: SonicWall SMA1000 Zero-Days Exploited](https://techleetsolutions.com/news/posts/2026-09-03-sonicwall-sma1000-zero-days-exploited?ref=badtech.org)