CVE-2026-83548
Published Sep 1, 2026
Last updated 9 hours ago
AI description
CVE-2026-83548 is identified as a pre-authentication Server-Side Request Forgery (SSRF) vulnerability present in the SonicWall SMA1000 Appliance WorkPlace interface. This flaw stems from an unintended alternate access path, which causes the appliance to function as an unintended forward proxy. Exploitation of this vulnerability allows a remote and unauthenticated attacker to gain unauthorized access to sensitive functionalities and execute unauthorized operations. This vulnerability is often discussed alongside CVE-2026-83549, a post-authentication operating system command injection vulnerability, as threat actors have been observed chaining these two flaws in attacks.
- Description
- A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
- Source
- PSIRT@sonicwall.com
- NVD status
- Analyzed
- Products
- sma8200v, sma6210_firmware, sma7210_firmware
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Exploit added on
- Sep 2, 2026
- Exploit action due
- Sep 5, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- PSIRT@sonicwall.com
- CWE-441
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
19
SonicWall SMA 1000 appliances under attack via zero-day flaws: attackers are exploiting CVE-2026-83548 and CVE-2026-83549. Patch/mitigate immediately, restrict admin access, and review logs for suspicious activity. #Cybersecurity https://t.co/kidXyVuB2Q
@VistemSolutions
3 Sept 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 SonicWall SMA1000 — two zero-days under active attack CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 are being exploited in the wild. The flaws may be chained to achieve unauthenticated RCE. https://t.co/PMuNmHsIvl #CVE #CVE202683548 #CVE202683549 #SonicWall #ZeroDay htt
@stem__shop
3 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers chained two SonicWall SMA1000 zero-days (CVE-2026-83548 & CVE-2026-83549) for remote code execution on VPN appliances. Initial SSRF-based command injection led to admin console privilege escalation. Runtime segmentation helps contain post-compromise pivoting from
@aviatrixtrc
3 Sept 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/5 SonicWall confirmed active exploitation of two SMA 1000 zero-days. CVE-2026-83548 is a pre-authentication SSRF rated CVSS 10.0. CVE-2026-83549 lets an authenticated administrator inject OS commands. Together, they may form an attack chain. 🧵 https://t.co/q4Ubk3Hdpr
@SOCMinute
2 Sept 2026
3 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Warnung vor zwei #Schwachstellen (CVE-2026-83548, CVE-2026-83549) in der #SMA1000-Series des Herstellers #SonicWall. Diese werden bereits bei Angriffen ausgenutzt, also patchen. https://t.co/Kt3I15Tcuk
@etguenni
2 Sept 2026
134 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New SonicWall zero-days (CVE-2026-83548, CVE-2026-83549) exploit SMA1000 appliances (Sept 2, 2026). This critical flaw allows remote access, threatening data privacy & integrity in transit for secure corporate communications. #Cybersecurity #ZeroDay #News
@YourAnon_irc
2 Sept 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 On 9/1/26, #SonicWall disclosed 2 EITW vulns affecting SonicWall SMA1000 appliances. CVE-2026-83548 & CVE-2026-83549 can be chained to achieve unauthenticated RCE on affected appliances. Find mitigation guidance and more in our blog: https://t.co/0FKR1nXe7h https://t.co
@rapid7
2 Sept 2026
2265 Impressions
0 Retweets
2 Likes
3 Bookmarks
0 Replies
0 Quotes
⚠️ ثغرتا يوم-صفر في سونيك وول تُستغلان معاً كسلسلة هجوم لتنفيذ أوامر عن بُعد بلا مصادقة. المعرّف : CVE-2026-83548 (10.0) / CVE-2026-83549 (7.8) الإصدارات المتأثرة : SMA 1000 <= v
@KasperskyDev
2 Sept 2026
307 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: Critical SSRF and #RCE in #SonicWall #SMA1000. CVE-2026-83548 & CVE-2026-83549 CVSS: 10. Attackers can gain access to sensitive functionality and inject OS commands. These are #ActivelyExploited ! More info in our advisory: https://t.co/PBw4KE0rM4 #Patch #Patch
@CCBalert
2 Sept 2026
198 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
csirt_it: ‼️ #Exploited #SonicWall: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-83548 e CVE-2026-83549 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Security Restrictions Bypass 🔗 https://t.co/KIhn1hmUvF ⚠️ Importante mante… https
@Vulcanux_
2 Sept 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall has disclosed two actively exploited zero-days in its SMA 1000 series (CVE-2026-83548 and CVE-2026-83549). These can be chained for unauthenticated remote code execution. Organizations using these appliances should apply patches immediately. #CyberSecurity
@Lumideezy
2 Sept 2026
216 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
1 Quote
‼️ #Exploited #SonicWall: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-83548 e CVE-2026-83549 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Security Restrictions Bypass 🔗 https://t.co/1LzZsaVZDO ⚠️ Importante mantenere aggiornati i s
@csirt_it
2 Sept 2026
286 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Two SonicWall SMA 1000 zero-days exploited in attack chain CVE-2026-83548 (CVSS 10.0) & CVE-2026-83549 — pre-auth SSRF + arbitrary file read. SonicWall warns both bugs are actively exploited. Patch now if you use SMA 1000 series. 🔗 https://t.co/5O3BrPuMkF
@CyberOSINTIO
2 Sept 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall a prévenu ses clients que des acteurs malveillants ont combinés deux nouvelles vulnérabilités zero-day dans SMA100 (CVE-2026-83548 et CVE-2026-83549) lors d'attaques par exécution de code arbitraire. https://t.co/338JFR3Tep
@cert_ist
2 Sept 2026
88 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall confirms active exploitation of two SMA1000 vulnerabilities: CVE-2026-83548 → pre-auth SSRF CVE-2026-83549 → OS command injection Vufay assessment: the bigger risk is not the appliance itself, but the trust boundary behind it. #Vufay #CyberSecurity #SonicWall htt
@vufaysecurity
2 Sept 2026
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
#SonicWall SMA1000 models affected by multiple #Vulnerabilities. Upgrade immediately. #CVE-2026-83548 #CVE-2026-83549 https://t.co/c089T6fttm
@NCIIPC
2 Sept 2026
271 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Alerte CERT-FR⚠️ Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance. Elles sont activement exploitées. https://t.co/ExJRzQSghz
@CERT_FR
2 Sept 2026
8434 Impressions
4 Retweets
6 Likes
1 Bookmark
0 Replies
1 Quote
Two chained SMA1000 zero-days getting actively exploited for unauthenticated RCE. CVE-2026-83549 and CVE-2026-83548 together let attackers in before auth even runs. If SMA1000 sits in front of any remote access path, patch or isolate it today - not next change window. h/t
@markovichio
2 Sept 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 SonicWall SMA 1000 sob ataque: duas falhas zero day estão sendo exploradas A SonicWall confirmou a exploração ativa das vulnerabilidades CVE-2026-83548 e CVE-2026-83549 em appliances SMA 1000, utilizados para acesso remoto seguro em ambientes corporativos. 🔍 A CVE ht
@TechStartXYZ
2 Sept 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SonicWall SMA 1000 sob ataque: duas falhas zero day estão sendo exploradas A SonicWall confirmou a exploração ativa das vulnerabilidades CVE-2026-83548 e CVE-2026-83549 em appliances SMA 1000, utilizados para acesso remoto seguro em ambientes corporativos. 🔍 A CVE 20
@TechStartXYZ
2 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall SMA 1000 appliances hand unauthenticated attackers remote code execution through two chained bugs. CVE-2026-83548 is a pre-auth SSRF in the Appliance Work Place interface on 6210, 7210, and 8200v running 12.4.3-03453 and earlier or 12.5.0-02835 and earlier.
@SecureChap
2 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New zero-days in SonicWall SMA 1000 exploited in the wild: a pre-auth SSRF (CVE-2026-83548) plus a post-auth command-injection (CVE-2026-83549) form an attack chain. Affected models 6210, 7210, 8200v must update to hotfix versions 12.4.3-03526 or 12.5.0-02952. Also review for htt
@dailytechonx
2 Sept 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy 2) CVE-2026-83549 - Post-authentication Remote Code Execution (RCE) Vulnerability SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities https://t.co/8li5ii75X8
@autumn_good_35
2 Sept 2026
473 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
🐦 🚨 Actively exploited: SonicWall SMA1000 CVE-2026-83548 (CVSS 10.0, pre-auth SSRF+RCE) and Langflow CVE-2026-0768 (CVSS 9.8, unauth RCE, still unpatched) — both used in live attacks, Langflow stealing OpenAI/AWS keys. Patch SonicWall ASAP. #infosec #CVE #0day
@ita_ipo
2 Sept 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall SMA 1000 appliances under attack via zero-day flaws: Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities… https://t.co/uJ7fNuXSS7 ht
@shah_sheikh
2 Sept 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall says attackers are chaining two actively exploited SMA1000 zero-days, CVE-2026-83548 and CVE-2026-83549, for remote code execution on 6210, 7210, and 8200v appliances. #SonicWall #SMA1000 #CVE202683548 https://t.co/JQBVpjJfzv
@TweetThreatNews
2 Sept 2026
226 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall SMA1000 zero-days. Already exploited. CVE-2026-83548 + CVE-2026-83549 Chained = RCE on the appliance Affected: 6210, 7210, 8200v Not affected: firewalls, SMA 100 Third SMA1000 zero-day since December. Patch today. Check your logs first. https://t.co/GsvkohYScr https:
@ThreatHunter_AI
2 Sept 2026
180 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks SonicWall SMA1000 vulnerabilities CVE-2026-83549 and CVE-2026-83548, which allow remote code execution, are being exploited in attacks. https://t.co/JZp0FjWKY1 https://t.co/VGAyKbdyWZ
@StetsonCG
2 Sept 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SonicWall SMA1000'de 2 Zero-Day Aktif İstismarda CVE-2026-83548 (CVSS 10.0) ve CVE-2026-83549 (CVSS 7.8) saldırılarda zincirlenebiliyor ve kimlik doğrulaması olmadan uzaktan kod çalıştırılmasına yol açabiliyor. SonicWall, SMA1000 cihazları için acil güncelle
@KubbeSiber
2 Sept 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
On Sept. 1, 2026, SonicWall confirmed active exploitation of CVE-2026-83548 and CVE-2026-83549 in SMA 1000 appliances. The flaws expose unauthenticated SSRF and post-admin-session code execution paths.
@Securehup
2 Sept 2026
17 Impressions
0 Retweets
3 Likes
0 Bookmarks
1 Reply
0 Quotes
Critical vulns in SonicWall SMA1000 appliances under active exploitation CVE-2026-83548 , CVE-2026-83549 -- https://t.co/DrL9XflBar
@AndreGironda
2 Sept 2026
199 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SonicWall SMA1000 vulnerabilities CVE-2026-83549 and CVE-2026-83548, which allow remote code execution, are being exploited in attacks. https://t.co/RBuQw41Tg9
@EduardKovacs
2 Sept 2026
358 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks: The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks… https://t.co/RYeW7DkBbo https
@shah_sheikh
2 Sept 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-83548 (CVSS 10.0) — SonicWall SMA1000 SSRF Exploited in the Wild Critical Vulnerability Alert! SonicWall SMA1000 is affected by CVE-2026-83548. 🔍 Identify Targets via ZoomEye: Search Dork: app="SonicWall SMA1000" Exposure: 5.4k instances identified globally.
@zoomeyebot
2 Sept 2026
35 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
@SonicWall discloses two critical flaws in SMA 1000 series appliances, including CVE-2026-83548 SSRF and CVE-2026-83549 OS command injection. CVE-2026-83548 allows unauthenticated remote access to restricted functions via the WorkPlace interface with a CVSS score of 10.0.
@WorldCyberNewsX
2 Sept 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-83548 が悪用されました: SMA1000 SSRF が 10.0 に到達 CVE-2026-83548 Exploited: SMA1000 SSRF Hits 10.0 #DailyCyberSecurity (Sep 1) https://t.co/y7qRsMeKsa
@foxbook
2 Sept 2026
231 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【また君か】SonciWall SMA1000にCVSSスコア10の脆弱性。CVE-2026-83548は無認証でのSSRF。認証後コマンドインジェクションのCVE-2026-83549と併せ修正されている。 https://t.co/l8MP4EVbrF
@__kokumoto
1 Sept 2026
843 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F160BF49-63F6-4458-AA1B-9D46AF320741",
"versionEndExcluding": "12.4.3-03526",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
"matchCriteriaId": "51E4FB42-435D-41F7-AF37-8235E3478CB5",
"versionEndExcluding": "12.5.0-02952",
"versionStartIncluding": "12.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:*",
"matchCriteriaId": "653B5F4D-7417-4A85-B385-46157A1540A6",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "796684A5-0639-4D62-8C3B-7E330F200964",
"versionEndExcluding": "12.4.3-03526",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22DA8C27-F1AF-4136-AB59-4E03350B68AD",
"versionEndExcluding": "12.5.0-02952",
"versionStartIncluding": "12.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7B24D300-1154-49A1-A1F3-FB0CC717166A",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "70103B37-D895-4F07-B927-7CD4DE85DB9C",
"versionEndExcluding": "12.4.3-03526",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ACADD37E-AEE1-4B8A-9D49-5AB22D53C393",
"versionEndExcluding": "12.5.0-02952",
"versionStartIncluding": "12.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E9B414C5-C376-4216-A267-ABC0930905CE",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]