TL;DR: SonicWall confirmed active exploitation of two SMA 1000 zero-day vulnerabilities this week, one an unauthenticated SSRF flaw rated CVSS 10.0. CISA added both to its Known Exploited Vulnerabilities catalog on September 2 and, unusually, ordered forensic triage rather than just patching, meaning organizations need to assume compromise until proven otherwise. This is for IT Directors and security leads at mid-market to enterprise organizations running SonicWall SMA 1000 or any internet-facing remote access appliance. On September 1, SonicWall disclosed that attackers are actively exploiting two previously unknown vulnerabilities in its SMA 1000 secure remote access appliances. Two days later, the Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 5 to act, with a directive that goes further than a normal patch order. What are the SonicWall SMA 1000 zero-day vulnerabilities? CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the SMA 1000 Appliance Work Place interface, rated CVSS 10.0, the maximum severity score. It lets an unauthenticated attacker reach internal functionality through an unintended access path. CVE-2026-83549 is an OS command injection flaw in the Appliance Management Console that normally requires admin credentials, but attackers are chaining it with the SSRF bug to run arbitrary commands with no authentication at all. Together, they add up to unauthenticated remote code execution on SMA 1000 6210, 7210, and 8200v models running firmware older than 12.4.3-03526 or 12.5.0-02952. Why did CISA order forensic triage instead of just patching? CISA marked both vulnerabilities as requiring forensic triage under Binding Operational Directive 26-04, not standard patch-and-move-on remediation. That distinction matters: it means CISA believes exposed appliances may already be compromised, and patching alone won’t tell you whether an attacker got in before the fix went live. For any organization running an affected appliance, the operating assumption should be breach until an investigation says otherwise, not “we patched it, we’re fine.” This follows a pattern INVITE’s security team has flagged before. Internet-facing remote access appliances, whether from SonicWall, Fortinet, Citrix, or Ivanti, are a preferred entry point precisely because they sit on the network edge with privileged access by design. When an AI-driven ransomware operation breached an unpatched, internet-exposed server earlier this year, the lesson was the same: unpatched edge devices are a live target, not a theoretical one. What should IT teams do right now? Four actions matter more than a general “stay vigilant” reminder: Apply SonicWall’s hotfix immediately: upgrade SMA 1000 appliances to 12.4.3-03526 or 12.5.0-02952 or later. If you can’t patch today, restrict Appliance Work Place and AMC access to trusted management networks only. Treat exposed appliances as potentially compromised: review authentication logs, admin console activity, and outbound connections for anything that predates today’s patch. Inventory every internet-facing remote access device, not just SonicWall. VPN gateways from any vendor are the recurring pattern in 2026’s KEV additions. Confirm monitoring covers your perimeter, not just endpoints. A compromised remote access appliance often shows up first in network traffic. How does INVITE help with vulnerabilities like this? INVITE’s managed cybersecurity team runs continuous vulnerability management and network security monitoring for clients across Salt Lake City and Phoenix, so a KEV addition like this one triggers an alert and a remediation plan the same day it’s published. As a Fortinet partner already helping clients harden VPN portals after this year’s FortiBleed campaign, INVITE applies the same playbook regardless of vendor: identify exposed appliances, patch or isolate, and verify nothing got in first. See INVITE’s enterprise cybersecurity services breakdown for the full program. Schedule a 30-minute architecture review with an INVITE security engineer if you’re running SonicWall SMA 1000 or any internet-facing remote access appliance and want a second set of eyes on your exposure. Frequently Asked Questions What is CVE-2026-83548? CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in SonicWall SMA 1000’s Appliance Work Place interface, rated CVSS 10.0. It allows an unauthenticated attacker to reach internal functionality through an unintended access path and is being actively exploited. Which SonicWall models are affected? SMA 1000 series models 6210, 7210, and 8200v running firmware versions 12.4.3-03453/12.5.0-02835 or older. SonicWall’s fix is 12.4.3-03526/12.5.0-02952 or later. What does it mean that CISA ordered “forensic triage”? Under Binding Operational Directive 26-04, forensic triage means organizations must investigate whether an exposed device was already compromised before this week’s fix, rather than assuming patching alone resolves the risk. Is this the first SSL VPN appliance zero-day this year? No. Citrix, Fortinet, and Ivanti VPN gateways have all had actively exploited zero-days added to CISA’s KEV catalog in 2026. Internet-facing remote access appliances remain one of the most consistently targeted device categories across vendors. What should we do if we don’t run SonicWall SMA 1000? Inventory every internet-facing remote access appliance in your environment regardless of vendor, confirm each one is on current firmware, and verify you have monitoring coverage at the network perimeter, not just on endpoints.