SonicWall security advisory (AV26-872) – Update 1
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 2 of 2 flaws named
- Flaws named
- CVE-2026-83548CVE-2026-83549
- Vendors and products
- SonicWall
- Industries
- Government
- Reported by
- 1 outlet
As of September 1, 2026, SonicWall is affected by a vulnerability in the following product:
- SMA1000 - 6210, 7210, 8200v
- 12.4.3-03453 (platform-hotfix) and older versions
- 12.5.0-02835 (platform-hotfix) and older versions
SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited.
Update 1
On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-8354810.0Critical
SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Used in attacksAdded to CISA's list 2026-09-02 · Patch or advisory available
Full record → - CVE-2026-835497.8High
SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Used in attacksAdded to CISA's list 2026-09-02 · Patch or advisory available
Full record →
Coverage
One outlet has carried this so far.
2026-09-02 18:44 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited