CVE-2026-83548
10.0 CISA KEVSonicWall · SMA1000
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
Executive summary
SonicWall SMA1000 appliances are subject to an actively exploited, critical SSRF vulnerability that permits unauthenticated remote attackers to bypass security controls and execute unauthorized operations.
Vulnerability
This vulnerability is a Server-Side Request Forgery (CWE-918) and a Confused Deputy (CWE-441) flaw located in the Work Place interface. An unauthenticated remote attacker can exploit an unintended alternate access path to interact with sensitive internal functionality without requiring any login credentials.
Business impact
The CVSS score of 10.0 reflects the critical nature of this flaw, as it allows full compromise of the appliance's confidentiality, integrity, and availability. Successful exploitation could lead to total system takeover, unauthorized access to sensitive internal network segments, or the exfiltration of corporate data. Given its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, the risk to business continuity and data security is extreme.
Remediation
Immediate Action: Administrators must immediately apply the latest vendor-supplied hotfixes or patches as detailed in the official SonicWall PSIRT advisory.
Proactive Monitoring: Security teams should monitor firewall and web application logs for suspicious requests directed at the Work Place interface, specifically looking for anomalous traffic patterns or unexpected internal connection attempts originating from the appliance.
Compensating Controls: If patching is not immediately feasible, restrict access to the affected web interface by placing it behind a robust Web Application Firewall (WAF) or limiting network access to trusted management IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the critical severity and confirmed active exploitation of this vulnerability, organizations must treat this as an emergency priority. All internet-facing SonicWall SMA1000 devices should be patched or taken offline until the appropriate vendor-supplied mitigations are successfully applied. Failure to act immediately significantly increases the likelihood of a successful compromise by malicious actors currently weaponizing this flaw.
More SonicWall CVEs
Sources
Originally found and disclosed by Adam Babis of SonicWall PSIRT, per the CVE Program record.