Cyber & AI intelligence
Wasteland.
Briefs indexed2377
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83548 2026-09-02

CVE-2026-83548: Pre-Auth SSRF in SonicWall SMA1000 Hits CVSS 10.0, Now in CISA KEV

"CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog on 2026-09-02, confirming active exploitation of a critical pre-authentication server-side request forgery flaw in SonicWall SMA1000 appliances."

CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog on 2026-09-02, confirming active exploitation of a critical pre-authentication server-side request forgery flaw in SonicWall SMA1000 appliances.

What Is It

A pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface, caused by an unintended alternate access path. A remote unauthenticated attacker could exploit it to gain unauthorized access to sensitive functionality and perform unauthorized operations.

The issue is tracked under CWE-918 (Server-Side Request Forgery) and CWE-441 (Unintended Proxy or Intermediary). It carries a CVSS 3.1 base score of 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with a changed scope and high impact to confidentiality, integrity, and availability.

Why It Matters

CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC assessment rates exploitation as active, automatable as yes, and technical impact as total: meaning attacks can be scripted at scale against exposed appliances for full compromise of the affected component.

SMA1000 appliances are internet-facing remote access gateways by design, so the unauthenticated attack path is directly reachable from the internet in typical deployments. Known ransomware campaign use is listed as Unknown. The KEV entry flags forensic triage as required.

What's Vulnerable

Per SonicWall's advisory data, the affected versions are:

NVD's CPE configurations cover the SMA 8200v virtual appliance, SMA 6210, and SMA 7210 firmware, with fixed versions at 12.4.3-03526 and 12.5.0-02952.

Patch Status

CISA set a due date of 2026-09-05: three days after the KEV addition. The required action: apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.

Sources