← Vulnerability feed

Vulnerability record · CVE-2026-83548 · published 1 September 2026

CVE-2026-83548: SonicWall SMA1000 pre-auth SSRF via alternate access path

Sonicwall · Sma8200v

The SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication. A remote unauthenticated attacker can use it to reach sensitive internal functionality and perform unauthorized operations. Because it is pre-auth, network-reachable and rated critical, it is a high-value target for edge-appliance compromise.

10.0 CVSS 3.1 Critical CISA KEV since 2 Sep 2026 EPSS 8.8% · top 5.0% CWE-441 · CWE-441CWE-918 · Server-side request forgery (SSRF)
10.0CVSS 3.1 base score
8.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
3 Sep 2026Last modified by NVD

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityPre-authentication, network-reachable SSRF with CVSS 10.0 and confirmed KEV listing with a near-term remediation deadline.

What it is

The SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication. A remote unauthenticated attacker can use it to reach sensitive internal functionality and perform unauthorized operations. Because it is pre-auth, network-reachable and rated critical, it is a high-value target for edge-appliance compromise.

Impact

An attacker gains unauthorized access to sensitive functionality and can perform unauthorized operations through the appliance, potentially reaching internal services via forged requests. The scope change in the CVSS vector indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network through the Work Place interface with no authentication and no user interaction required (AV:N/PR:N/UI:N). The unintended alternate access path is the entry point; no credentials or victim action are needed.

Exploitation

CISA added it to KEV on 2026-09-02 with a remediation due date of 2026-09-05, indicating known exploitation. EPSS 30-day probability is 0.04667 (91st percentile); no ransomware campaign use is documented.

What to do

  • Apply the SonicWall vendor fix per advisory SNWLID-2026-0016 immediately; treat the 2026-09-05 KEV due date as the deadline.
  • If a patch is not yet available, follow CISA BOD 26-04 guidance: apply vendor mitigations or discontinue use of the exposed product.
  • Remove or restrict internet exposure of the SMA1000 Work Place interface until patched.
  • Restrict outbound traffic from the appliance to only required destinations to blunt SSRF reach into internal networks.
  • Verify no unauthorized configuration or account changes were made before patching.

Detection

  • Review appliance and perimeter logs for requests to the Work Place interface from unauthenticated or unexpected sources, especially to unusual paths.
  • Monitor outbound connections originating from the SMA1000 to internal or unfamiliar external hosts for SSRF patterns.
  • Alert on configuration changes, new accounts or administrative actions on the appliance outside change windows.
  • Hunt for known exploitation indicators from vendor and CISA guidance for this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-83548 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed9.8CVE-2025-23006SonicWall SMA1000 pre-auth deserialization allows OS command executionThe SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific condition…KEVEPSS 23%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed6.6CVE-2025-40602SonicWall SMA1000 management console missing authorization privilege escalationThe SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to C…KEVEPSS 2.8%analysed7.2CVE-2026-4116Sonicwall sma6210 firmware vulnerabilityImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu…EPSS 0.71%7.2CVE-2026-4112Sonicwall sma6210 firmware sql injection vulnerabilityImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic…EPSS 0.53%7.2CVE-2026-4113Sonicwall sma6210 firmware vulnerabilityAn observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2026-83548), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.