SonicWall's SMA1000 series — an appliance many businesses use to give staff secure remote access into the office network — has two chained vulnerabilities that let an attacker take full control of it with no password at all, and SonicWall has confirmed they're already being used in the wild. If your business, or whoever manages your network, runs an SMA1000 (the 6210, 7210 or 8200v models), the priority this week is patching it and checking whether it was already accessed, not just patching it.
What actually happened
On 1 September 2026, SonicWall disclosed two flaws in the SMA1000's Work Place and Appliance Management Console interfaces. CVE-2026-83548 is an unauthenticated server-side request forgery bug with the maximum possible severity score, 10.0 out of 10 — an attacker needs no login at all to reach it. CVE-2026-83549 is a command-injection flaw in the management console that, on its own, needs administrator access. Chained together, the first flaw hands an attacker exactly the access the second one needs, and the result is remote code execution on the appliance from the open internet, no credentials required.
SonicWall confirmed active exploitation and shipped fixed firmware the same day (builds 12.4.3-03526 and 12.5.0-02952). The US Cybersecurity and Infrastructure Security Agency added both CVEs to its Known Exploited Vulnerabilities catalogue with a remediation deadline of 5 September — four days after disclosure, which is CISA's way of saying "this is being actively used against real organisations, now."
Why a VPN appliance is a high-value target
An SMA1000 isn't just another server on the network — it's the front door for remote staff, purpose-built to sit on the internet and accept connections from outside. That's exactly why an unauthenticated flaw in one is so serious: there's no phishing email to fall for and no password to guess. The device is designed to be reachable, and once an attacker owns it, they inherit the same trusted path into the internal network that your own staff use to work from home.
This is the third time in a matter of weeks that a remote-access or firewall product has turned up in an active-exploitation advisory — Check Point's VPN clients and a chained Windows VPN flaw both made headlines earlier in September. Taken together, it's a clear pattern rather than a one-off: the appliances businesses rely on for secure remote work are the thing attackers are probing hardest right now, precisely because compromising one is worth more than compromising any single desktop.
Patching isn't the whole job here
Because CVE-2026-83548 requires no authentication, a device left unpatched for even a few days between disclosure and today should be treated as possibly already accessed, not just vulnerable. SonicWall's own advisory recommends reviewing logs for the period before the hotfix was applied, not simply installing the fix and moving on. That distinction matters: a patch closes the door, but it doesn't undo anything that happened while it was open.
What to check this week
- Ask directly whether your business (or your IT provider, on your behalf) runs a SonicWall SMA1000. Not every business will — it's a mid-to-enterprise-tier appliance — but if remote staff connect through one, this affects you.
- Confirm the firmware is on build 12.4.3-03526 or 12.5.0-02952 or later. Anything earlier than that is the vulnerable range.
- Ask whether anyone has reviewed access logs from before the patch was applied, not just whether the patch itself has gone in.
- If you can't get a straight answer to any of the above, treat that as the answer. A provider managing internet-facing infrastructure should know its patch status without having to go and check.
The broader habit worth building
Most Perth businesses don't manage their own remote-access appliance directly — it's usually the IT provider's job. But that's exactly why it's worth asking about rather than assuming it's handled. Internet-facing devices — VPN gateways, firewalls, remote-access portals — need to be patched faster than internal systems, because they're the ones an attacker can reach without ever setting foot inside your network. A device that's a week behind on an internal server patch is a minor gap; a device that's a week behind on an internet-facing one, during active exploitation, is an open door.
None of this is a reason to stop offering staff remote access — the fix for a vulnerable front door isn't to stop using doors, it's to keep the lock current and know when it's been tried. Patch the exposed edge fast, and make sure a single compromised device — however well trusted — can't take the rest of the business down with it.
What we do
Patching internet-facing infrastructure — firewalls, VPN gateways, remote-access appliances — the day a fix ships, not the week we get around to it, is part of our firewall security management and IT security solutions. If you're not sure what's sitting on the edge of your network or when it was last patched, that's worth finding out.
Get in touch or call (08) 9325 1196 — we've been keeping Perth businesses' networks properly looked after since 1997.



