SonicWall is warning that attackers are chaining two flaws in its SMA1000 remote access appliances into unauthenticated remote code execution. The company disclosed both on September 1 in advisory SNWLID-2026-0016 after its product security team investigated an attack that combined them against a customer. Affected models are the SMA 6210, 7210, and the virtual 8200v.

CVE-2026-83548 is a pre-authentication server-side request forgery in the Appliance Work Place interface that allows command injection, base score 10.0. CVE-2026-83549 is an OS command injection in the Appliance Management Console, base score 7.8, and normally requires administrator credentials. Chained behind the first flaw, it needs none.

Fixes shipped as platform hotfixes 12.4.3-03526 and 12.5.0-02952. Builds at 12.4.3-03453 or 12.5.0-02835 and earlier are vulnerable. SSL-VPN on SonicWall firewalls and the SMA 100 series are not affected.

CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 3. Shadowserver counts roughly 400 SMA1000 appliances reachable from the internet, most of them in the United States, and some of those front remote access for health systems and their vendors. HIPAA Journal pushed the warning to the healthcare sector on September 4.

The SMA1000 line has been here before. Attackers exploited CVE-2026-15409 and CVE-2026-15410 in July 2026 to plant custom malware on the appliances, and a December 2025 chain built on CVE-2025-40602 reached root. For device manufacturers the box matters less as a product than as a path: these appliances commonly terminate the remote access that service engineers and suppliers use to reach production and clinical networks.

Three rounds of exploited zero days since December is a track record, and it belongs in the vendor risk file next to the CVSS scores. A patch applied after exposure does not evict anyone who arrived first, so budget for log review and credential rotation on every appliance that sat on the internet unpatched.