• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-83548: pre-auth server-side request forgery in SonicWall SMA1000 Appliances

Remote, unauthenticated attackers can exploit a pre-authentication SSRF flaw in SonicWall SMA1000 Appliances to access sensitive functionality and perform unauthorized operations; see CVE-2026-83548. The issue exists in the Work Place interface via an unintended alternate access path. Affected releases include 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older. An attacker only needs network access to the SMA1000 appliance (for example, an internet-facing or reachable management interface) to attempt exploitation.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.08757
CWE
CWE-918
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent—CISA added CVE-2026-83548 to its Known Exploited Vulnerabilities catalog with a near-term remediation deadline, so prioritize applying vendor mitigations immediately and isolate exposed SMA1000 devices.

What is CVE-2026-83548?

Remote, unauthenticated attackers can exploit a pre-authentication SSRF flaw in SonicWall SMA1000 Appliances to access sensitive functionality and perform unauthorized operations; see CVE-2026-83548. The issue exists in the Work Place interface via an unintended alternate access path. Affected releases include 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older. An attacker only needs network access to the SMA1000 appliance (for example, an internet-facing or reachable management interface) to attempt exploitation. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of SonicWall SMA1000 Appliances are affected?

BRANCHAFFECTEDFIXED
12.x12.4.3-03453 (platform-hotfix) and older versions
12.x12.5.0-02835 (platform-hotfix) and older versions

Is CVE-2026-83548 being exploited?

CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog on 2026-09-02, and U.S. federal agencies were required to follow the listed mitigation/remediation steps by 2026-09-05; public exploit code is also available.

How to fix CVE-2026-83548

  1. Apply any vendor-provided mitigations or guidance for SMA1000 Appliances immediately.
  2. Restrict network exposure of SMA1000 devices—limit management interfaces to trusted networks and VPNs.
  3. Monitor appliance logs and network traffic for signs of SSRF exploitation or unexpected backend requests.
  4. If mitigations are unavailable or cannot be applied, follow CISA guidance and consider discontinuing use or isolating affected appliances.

Frequently asked questions

Is CVE-2026-83548 being actively exploited?

CISA added CVE-2026-83548 to its Known Exploited Vulnerabilities catalog on 2026-09-02, and public exploit code is available.

Which SMA1000 Appliances versions are affected by CVE-2026-83548?

SMA1000 Appliances affected include 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older.

Is there a patch for CVE-2026-83548?

As of 2026-09-29 there is no patch listed; follow vendor mitigations and CISA guidance.

Does CVE-2026-83548 require authentication?

No. The vulnerability is a pre-authentication SSRF in the SMA1000 Work Place interface and can be triggered by a remote unauthenticated attacker with network access to the appliance.

References