CVE-2026-83548
published 2026-09-01CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote…
PriorityP195critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-05
Exploited in the wild
EPSS
7.45%
94.1th percentile
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sonicwall | sma1000 | — | — |
| sonicwall | sma1000 | — | — |
| sonicwall | sma6210_firmware | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall | sma6210_firmware | >= 12.5.0 < 12.5.0-02952 | 12.5.0-02952 |
| sonicwall | sma7210_firmware | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall | sma7210_firmware | >= 12.5.0 < 12.5.0-02952 | 12.5.0-02952 |
| sonicwall | sma8200v | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall | sma8200v | >= 12.5.0 < 12.5.0-02952 | 12.5.0-02952 |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
ghsa_unreviewed·2026-09-02
CVE-2026-83548 CWE-441 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
VulDB
SonicWall SMA1000 Work Place Interface server-side request forgery
vuldb·2026-09-01
CVE-2026-83548 [CRITICAL] SonicWall SMA1000 Work Place Interface server-side request forgery
A vulnerability described as critical has been identified in SonicWall SMA1000. This impacts an unknown function of the component Work Place Interface. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-83548. The attack may be launched remotely. There is no exploit available.
VulnCheck
Unintended Proxy or Intermediary ('Confused Deputy')
vulncheck·2026
CVE-2026-83548 Unintended Proxy or Intermediary ('Confused Deputy')
Unintended Proxy or Intermediary ('Confused Deputy')
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://previdian.com/CVE-2026-83548; https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
CISA
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
cisa·2026-09-02·CVSS 10.0
CVE-2026-83548 [CRITICAL] CWE-918 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Vulnerability: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Affected: SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure
No detection rules found.
Metasploit
SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
metasploit·CVSS 10.0
CVE-2026-83548 [CRITICAL] SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
This module chains three issues in SonicWall SMA1000 appliances. An unauthenticated, absolute-form OPTIONS request makes the WorkPlace listener act as an unintended forward proxy (CVE-2026-83548). The module uses this access and a vendor-installed CouchDB update handler to obtain read and write access to loopback CouchDB (SMA1000-9427), then enables CouchDB's native Erlang query server and executes one command as the couchdb service account. That command derives the appliance-local ctrl-service credential and invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap script (CVE-2026-83549) executes the selected command as root. The module attempts to restore the original CouchDB logger configuration, remove its inj
Nuclei
SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
nuclei·CVSS 10.0
CVE-2026-83548 [CRITICAL] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
Template:
id: CVE-2026-83548
info:
name: SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
author: rapid7,DhiyaneshDk
severity: critical
description: |
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
impact: |
A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
remediation: |
Apply SonicWall platform hotfix 12.4.3-03526 (12.4.x) or 12.5.0-02952 (12.5.x) immediately.
referenc
Checkpoint
7th September – Threat Intelligence Report
blogs_checkpoint·2026-09-07
CVE-2026-83548 7th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information.
Hit, a major Slovenian gambling and tour
Hackernews
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
blogs_hackernews·2026-09-03·CVSS 6.5
CVE-2026-83548 [MEDIUM] CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog after they landed in attackers' crosshairs.
The vulnerabilities are as follows -
CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVE-2026-83549 (CVSS score: 7.8) - A post-authen
Hackernews
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
blogs_hackernews·2026-09-02·CVSS 10.0
CVE-2026-83548 [CRITICAL] Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
The vulnerabilities , discovered internally by SonicWall's William Perry and Adam Babis, are listed below -
CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Rapid7
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
blogs_rapid7·2026-09-02·CVSS 10.0
CVE-2026-83548 [CRITICAL] Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
## Overview
On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances.
CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path.
CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its
2026-09-01
Published
2026-09-02
Added to CISA KEV
Exploited in the wild