SonicWall SMA1000 CVE-2026-83548 and CVE-2026-83549 are being actively exploited, and administrators should check the exact platform-hotfix running on affected SMA1000 appliances. SonicWall identifies SMA1000 models 6210, 7210 and 8200v in the affected product scope. For the 12.4.3 branch, platform-hotfix 12.4.3-03453 and earlier is affected and 12.4.3-03526 is the vendor-listed fixed hotfix. For the 12.5.0 branch, 12.5.0-02835 and earlier is affected and 12.5.0-02952 is the vendor-listed fixed hotfix.
The immediate job is not only to install a fixed build. Because SonicWall confirms active exploitation, organizations that were running an affected version should also follow the vendor’s compromise-review guidance. A newly patched appliance is in a different current software state, but patching by itself does not establish that the appliance was never compromised before remediation.
SonicWall SMA1000 CVE-2026-83548: the direct answer
If your SMA1000 6210, 7210 or 8200v is running platform-hotfix 12.4.3-03453 or earlier, move to 12.4.3-03526 or a later vendor-supported fixed hotfix. If it is running 12.5.0-02835 or earlier, move to 12.5.0-02952 or a later vendor-supported fixed hotfix. Because these vulnerabilities are actively exploited, SonicWall also directs affected customers to seek assistance reviewing the system for indicators of compromise.

Which SMA1000 models and builds are affected?
SonicWall’s product notice applies to the SMA1000 series models listed below. The platform-hotfix suffix matters: a branch name such as 12.4.3 or 12.5.0 is not enough by itself to determine whether the appliance is fixed.
| Model scope | Affected platform-hotfix | Vendor-listed fixed platform-hotfix |
|---|---|---|
| SMA 6210, 7210, 8200v | 12.4.3-03453 and earlier | 12.4.3-03526 |
| SMA 6210, 7210, 8200v | 12.5.0-02835 and earlier | 12.5.0-02952 |
Administrators should compare the complete platform-hotfix value shown on the appliance with SonicWall’s current advisory. A newer vendor-supported hotfix may supersede the fixed versions listed here later, so the current SonicWall guidance should control the final remediation decision.
What is the difference between CVE-2026-83548 and CVE-2026-83549?
CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability affecting the Work Place interface. It is the higher-severity issue in the pair.
CVE-2026-83549 is an operating-system command-injection vulnerability in the Appliance Management Console. Considered by itself, its documented conditions include authenticated administrator access and additional prerequisites. The two CVEs should therefore not be described as identical flaws even though SonicWall disclosed them together and confirms active exploitation associated with the current SMA1000 security event.
Are the SonicWall SMA1000 vulnerabilities actively exploited?
Yes. SonicWall’s own product notice states that CVE-2026-83548 and CVE-2026-83549 are being actively exploited. CERT-In subsequently issued an India-facing vulnerability note identifying the affected SMA1000 models and platform-hotfix boundaries.
This means administrators should treat the issue as an active defensive remediation problem rather than a theoretical vulnerability that can simply be placed into a routine future patch queue.
What should an SMA1000 administrator do now?
1. Identify the appliance model
Confirm whether the deployment is an SMA1000 6210, 7210 or 8200v covered by the vendor notice.
2. Record the full platform-hotfix
Do not stop at the branch number. Compare the complete hotfix value against the affected and fixed boundaries.
3. Move affected 12.4.3 systems to a fixed hotfix
If the appliance is on 12.4.3-03453 or earlier, SonicWall lists 12.4.3-03526 as the corresponding fixed platform-hotfix.
4. Move affected 12.5.0 systems to a fixed hotfix
If the appliance is on 12.5.0-02835 or earlier, SonicWall lists 12.5.0-02952 as the corresponding fixed platform-hotfix.
5. Treat prior exposure as a separate question
If the appliance was running an affected version while exploitation was active, follow SonicWall’s compromise-review guidance instead of treating the new version number as proof that no prior compromise occurred.
Is patching enough after active exploitation?
Not necessarily. SonicWall tells customers running affected versions to upgrade and to contact SonicWall Technical Support for assistance reviewing the system for indicators of compromise.
The distinction is important:
- Upgrade: moves the appliance out of the documented vulnerable software state when the appropriate fixed hotfix is installed.
- Compromise review: asks whether exploitation may already have occurred before the appliance was remediated.
TPS did not establish a complete public universal indicator list from the reviewed vendor guidance. Administrators should not invent their own clean-host conclusion merely because one public indicator is absent.
What should you do if indicators of compromise are found?
SonicWall’s current guidance says that when indicators of compromise are detected, affected organizations should take additional recovery action rather than relying only on an in-place hotfix.
- Re-image affected hardware appliances or redeploy affected virtual appliances.
- Change user passwords.
- Change administrator passwords.
- Reset TOTP tokens.
Those actions are conditional on the compromise state described by the vendor. TPS is not asserting that every affected appliance must automatically be reimaged when no compromise has been established.
Is there a workaround instead of installing the fixed hotfix?
No substitute workaround was established in the reviewed SonicWall guidance. The vendor response is to upgrade affected appliances to the applicable fixed or later supported hotfix and complete the recommended compromise review.
Administrators should use current SonicWall guidance if the vendor later publishes a mitigation, revised fix boundary or additional platform branch.
Does the CISA September 5 deadline apply to Indian or private organizations?
Not automatically. CISA’s Known Exploited Vulnerabilities catalog is important evidence that a vulnerability is being exploited, but remediation deadlines under the applicable U.S. federal directive govern covered U.S. federal civilian agencies. TPS does not treat that federal deadline as a universal legal deadline for Indian private organizations or other non-covered entities.
Organizations should separately follow their own regulatory, contractual and incident-response obligations together with SonicWall’s current technical guidance and relevant national CERT advice.
What remains unresolved?
- The total number of compromised organizations is not established by the reviewed primary sources.
- The number of compromised organizations in India is unknown.
- A complete public universal IOC set was not established from the reviewed SonicWall notice.
- Attacker or campaign attribution is not established here.
- An affected platform-hotfix does not prove that a specific appliance was successfully exploited.
- A fixed platform-hotfix does not prove that earlier compromise did not occur.
- It is not established that every observed exploitation incident used both CVEs in exactly the same sequence.
Verification method
ThePulseSignal reviewed SonicWall’s current SMA1000 product notice for affected models, affected platform-hotfixes, fixed hotfixes, exploitation status and compromise-response instructions. CERT-In’s India-facing vulnerability note was used to independently reconcile the affected-build and active-exploitation state.
Frequently asked questions
Is SonicWall SMA1000 CVE-2026-83548 actively exploited?
Yes. SonicWall confirms active exploitation in its product notice covering CVE-2026-83548 and CVE-2026-83549.
Is SMA1000 platform-hotfix 12.4.3-03453 affected?
Yes. SonicWall lists 12.4.3-03453 and earlier as affected and 12.4.3-03526 as the corresponding fixed platform-hotfix.
Is SMA1000 platform-hotfix 12.5.0-02835 affected?
Yes. SonicWall lists 12.5.0-02835 and earlier as affected and 12.5.0-02952 as the corresponding fixed platform-hotfix.
Which SMA1000 models are covered by the advisory?
The vendor notice covers SMA1000 models 6210, 7210 and 8200v.
Does installing the fixed hotfix prove the appliance is clean?
No. Installing a fixed build addresses the documented vulnerable software state, but SonicWall also directs affected customers to perform compromise review. A previously exposed appliance may require additional incident-response action.
What happens if compromise indicators are found?
SonicWall advises reimaging hardware appliances or redeploying virtual appliances and changing user and administrator passwords and TOTP tokens when indicators of compromise are detected.



