CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog on 2026-09-02, confirming active exploitation of a critical pre-authentication server-side request forgery flaw in SonicWall SMA1000 appliances.
What Is It
A pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface, caused by an unintended alternate access path. A remote unauthenticated attacker could exploit it to gain unauthorized access to sensitive functionality and perform unauthorized operations.
The issue is tracked under CWE-918 (Server-Side Request Forgery) and CWE-441 (Unintended Proxy or Intermediary). It carries a CVSS 3.1 base score of 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with a changed scope and high impact to confidentiality, integrity, and availability.
Why It Matters
CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC assessment rates exploitation as active, automatable as yes, and technical impact as total: meaning attacks can be scripted at scale against exposed appliances for full compromise of the affected component.
SMA1000 appliances are internet-facing remote access gateways by design, so the unauthenticated attack path is directly reachable from the internet in typical deployments. Known ransomware campaign use is listed as Unknown. The KEV entry flags forensic triage as required.
What's Vulnerable
Per SonicWall's advisory data, the affected versions are:
- SMA1000 12.4.3-03453 (platform-hotfix) and older
- SMA1000 12.5.0-02835 (platform-hotfix) and older
NVD's CPE configurations cover the SMA 8200v virtual appliance, SMA 6210, and SMA 7210 firmware, with fixed versions at 12.4.3-03526 and 12.5.0-02952.
Patch Status
CISA set a due date of 2026-09-05: three days after the KEV addition. The required action: apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Sources
- SonicWall PSIRT Advisory SNWLID-2026-0016; https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548
- NVD, CVE-2026-83548, https://nvd.nist.gov/vuln/detail/CVE-2026-83548
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements), https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk