Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026-0016)

1788278427

Overview

  • CVE-2026-83548: Pre-authentication SSRF via unintended forward-proxy - CVSS Score: 10.0 (Critical)
  • CVE-2026-83549: Post-authentication Remote Code Execution (RCE) Vulnerability – CVSS Score: 7.8 (High) 

SonicWall Secure Mobile Access 1000 Series 12.4.3 and 12.5.0 firmware (see impacted versions) are affected by multiple vulnerabilities.   

IMPORTANT: These vulnerabilities have been confirmed as being actively exploited in the wild.  

These vulnerabilities are unrelated to any other reported vulnerability on other SonicWall products.

Product Impact 

Please review the table below to see the products and their versions that are impacted:

Impacted Product(s) 

Impacted Versions (platform-hotfix)

SMA 1000 (6210, 7210, 8200v - all hypervisors) 

12.4.3-03453 (all versions)

12.5.0-02835 (all versions)

Remediation 

Impacted Product(s) 

Impacted Versions (platform-hotfix)

Fixed Version 

SMA 1000 (6210, 7210, 8200v - all hypervisors)  

12.4.3-03453 (all versions)

12.5.0-02835 (all versions)

12.4.3-03526 

12.5.0-02952 

All organizations with deployments of SMA1000 appliances (whether virtual or physical) on affected versions must perform the following:

  • Upgrade to the latest hotfix version – available via https://www.mysonicwall.com
  • Contact SonicWall Technical Support for assistance reviewing the system for indicators of compromise (IoCs)
  • If IoCs are detected on the system:
    • Re-image (hardware) or re-deploy (virtual) appliances.
    • Change all user and administrator passwords.
    • Reset TOTP tokens.

SonicWall strongly advises Secure Mobile Access customers on affected versions follow the guidance provided. 

Related information 

  • Previous Alert
    Product Notice: SonicWall GMS Security Affected By Multiple Vulnerabilities
    Read More