On September 1, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected.
CVE-2026-83548 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface. According to the SonicWall advisory, an attacker could exploit this issue to “gain unauthorized access to sensitive functionality and perform unauthorized operations.”
CVE-2026-83549 is a high-severity (CVSS score of 7.8) OS command injection vulnerability in the Appliance Management Console (AMC) that arises from improper neutralization of special elements. In specific conditions, it could “enable a remote attacker authenticated as an administrator to execute arbitrary OS commands, resulting in remote code execution.”
SonicWall confirmed exploitation of these vulnerabilities in the wild.
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable SonicWall appliances in their environments and upgrade as appropriate as soon as possible.
Sophos countermeasures
SophosLabs continues to monitor the threat landscape for activity related to these vulnerabilities and will deliver detections and protections as available.

