The Exploit Bulletin — Wednesday, September 2, 2026: 1 issue requires action
Wednesday, September 2, 2026 — 1 issue requires action. If you run none of the software below, you are done.
Affects: SonicWall
1. Pre-auth SSRF chained to unauthenticated remote code execution on SonicWall SMA1000 VPN appliances (CVE-2026-83548)
REMOTE CODE EXECUTION · CRITICAL · CVSS 10.0
SonicWall published fixes on September 1 for two SMA1000 zero-days that credible outlets and the Canadian Cyber Centre report are being chained in live attacks, so an unpatched appliance is exposed to unauthenticated remote code execution right now.
A pre-authentication SSRF in the SMA1000 Work Place interface (CVE-2026-83548, CVSS 10.0) gives a remote unauthenticated attacker access to sensitive functionality, and it is being chained with sibling flaw CVE-2026-83549 to achieve unauthenticated remote code execution on the appliance. SMA1000 6210, 7210, and 8200v devices running 12.4.3-03453 (platform-hotfix) and older or 12.5.0-02835 (platform-hotfix) and older are affected.
Affected: SonicWall SMA1000 (6210, 7210, 8200v) 12.4.3-03453 (platform-hotfix) and older; SonicWall SMA1000 (6210, 7210, 8200v) 12.5.0-02835 (platform-hotfix) and older
How to Test: Check the appliance firmware version: any SMA1000 running 12.4.3-03453 (platform-hotfix) or older, or 12.5.0-02835 (platform-hotfix) or older, is vulnerable. Review appliance logs for unexpected or anomalous requests to the Work Place interface from unauthenticated sources, and treat any exposed, unpatched device as potentially compromised given zero-day exploitation preceded the fix.
How to Patch: Apply the security updates SonicWall released under advisory SNWLID-2026-0016, upgrading beyond the affected 12.4.3-03453 and 12.5.0-02835 platform-hotfix builds on all SMA1000 6210, 7210, and 8200v units; if a device cannot be updated immediately, restrict internet access to the Work Place interface until it is patched.
Evidence: VulnCheck KEV · Canadian Centre for Cyber Security advisory AV26-872 on exploited SMA1000 flaws · BleepingComputer: SonicWall warns of actively exploited SMA1000 zero-days · The Hacker News: two SMA1000 zero-days exploited as an attack chain · SecurityWeek: SMA1000 zero-days chained for unauthenticated RCE
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].