The U.S. Cybersecurity and Infrastructure Security Agency has added two SonicWall SMA1000 appliance vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming that attackers are exploiting the flaws in real-world attacks.
The entries were added on September 2, 2026, with federal civilian agencies required to address the risks by September 5, 2026. The vulnerabilities affect SonicWall SMA1000 appliances, which are commonly used to provide secure remote access to enterprise networks.
Because these systems can sit at the edge of an organization’s network and handle privileged user connections, successful exploitation could provide attackers with a path to sensitive internal systems.
SonicWall SMA1000 Vulnerabilities Exploited
CVE-2026-83549 is an OS command injection vulnerability tracked as CWE-78. According to the CISA entry, a remote attacker already authenticated as an administrator could exploit the flaw to run arbitrary operating system commands on a vulnerable appliance.
This could result in remote code execution, enabling an attacker to execute commands, alter appliance settings, establish persistence, or potentially move deeper into a connected environment.
The second issue, CVE-2026-83548, is a server-side request forgery vulnerability associated with CWE-918 and CWE-441. Unlike the command injection flaw, this vulnerability could allow a remote unauthenticated attacker to access sensitive functionality and perform unauthorized operations.
Server-side request forgery, often abbreviated as SSRF, can be dangerous because it tricks a vulnerable system into making requests that an external attacker could not make directly.
CISA has marked both flaws as requiring forensic triage under Binding Operational Directive 26-04. This means affected organizations should not treat the issue as a routine patching event.
Security teams should assess whether SMA1000 appliances are internet-facing, review authentication and administrative activity, and investigate for unusual requests, configuration changes, new accounts, unexpected processes, or suspicious outbound connections.
Although CISA’s catalog entries list ransomware use as unknown, active exploitation significantly raises the urgency. Threat actors regularly target VPN and remote-access appliances because they can expose high-value access points to corporate environments.
Organizations using SonicWall SMA1000 devices should immediately apply the vendor-provided mitigations and follow the relevant CISA risk-based patching and forensic-triage guidance. If mitigations are unavailable, CISA advises organizations to consider discontinuing use of the affected product.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks appeared first on Cyber Security News.
