cbcvebase.
CVE-2026-83548
published 2026-09-01

CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote…

PriorityP195critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-05
Exploited in the wild
EPSS
7.45%
94.1th percentile
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Affected

8 ranges
VendorProductVersion rangeFixed in
sonicwallsma1000
sonicwallsma1000
sonicwallsma6210_firmware< 12.4.3-0352612.4.3-03526
sonicwallsma6210_firmware>= 12.5.0 < 12.5.0-0295212.5.0-02952
sonicwallsma7210_firmware< 12.4.3-0352612.4.3-03526
sonicwallsma7210_firmware>= 12.5.0 < 12.5.0-0295212.5.0-02952
sonicwallsma8200v< 12.4.3-0352612.4.3-03526
sonicwallsma8200v>= 12.5.0 < 12.5.0-0295212.5.0-02952

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.