[NEW] [critical] SonicWall SMA: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in SonicWall SMA to bypass security measures and execute code with administrator privileges.
CSIRTS triage
- What
- Multiple vulnerabilities permit authentication bypass and code execution with administrator privileges.
- Who is affected
- Organizations deploying SonicWall SMA appliances.
- Urgency
- Critical; allows administrative access and full system compromise.
- Action
- Apply the security patches from SonicWall immediately and verify no unauthorized access has occurred.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SMA
Get an email when a new SMA advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3135
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-83548Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 18% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-83549Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 58% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-83548 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-83549 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedSonicWall security advisory (AV26-872) – Update 1cccs
- highexploitedCISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedNCSC-2026-0337 [1.00] [H/H] Zero-Day vulnerabilities patched in SonicWall SMA1000 Appliancencsc-nl
- criticalexploitedCVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerabilitycisa-kev
- unknownexploitedMultiple vulnerabilities in SonicWall Secure Mobile Access (02 September 2026)cert-fr-alerte
- unknownexploitedMultiple vulnerabilities in SonicWall products (02 September 2026)cert-fr-avis
- criticalexploitedCVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa-kev
- highexploitedCVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Com…nvd
- criticalexploitedCVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface d…nvd
Recent advisories for SonicWall SMA
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] SonicWall SMA: Multiple vulnerabilitiescert-bund · 2026-07-15
- criticalexploitedCVE-2021-20038: SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerabilitycisa-kev · 2022-01-28
More from CERT-Bund (BSI) Security Advisories
- critical[NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privileges2026-09-03
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-09-02
- high[UPDATE] [high] Golang Go: Multiple vulnerabilities2026-09-02
- medium[NEW] [medium] Node.js: Multiple vulnerabilities2026-09-02
- high[NEW] [high] Microsoft GitHub Enterprise Server: Multiple vulnerabilities2026-09-02