CVE-2026-83548

10.0 CISA KEV

SonicWall · SMA1000

A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.

Executive summary

SonicWall SMA1000 appliances are subject to an actively exploited, critical SSRF vulnerability that permits unauthenticated remote attackers to bypass security controls and execute unauthorized operations.

Vulnerability

This vulnerability is a Server-Side Request Forgery (CWE-918) and a Confused Deputy (CWE-441) flaw located in the Work Place interface. An unauthenticated remote attacker can exploit an unintended alternate access path to interact with sensitive internal functionality without requiring any login credentials.

Business impact

The CVSS score of 10.0 reflects the critical nature of this flaw, as it allows full compromise of the appliance's confidentiality, integrity, and availability. Successful exploitation could lead to total system takeover, unauthorized access to sensitive internal network segments, or the exfiltration of corporate data. Given its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, the risk to business continuity and data security is extreme.

Remediation

Immediate Action: Administrators must immediately apply the latest vendor-supplied hotfixes or patches as detailed in the official SonicWall PSIRT advisory.

Proactive Monitoring: Security teams should monitor firewall and web application logs for suspicious requests directed at the Work Place interface, specifically looking for anomalous traffic patterns or unexpected internal connection attempts originating from the appliance.

Compensating Controls: If patching is not immediately feasible, restrict access to the affected web interface by placing it behind a robust Web Application Firewall (WAF) or limiting network access to trusted management IP addresses only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical severity and confirmed active exploitation of this vulnerability, organizations must treat this as an emergency priority. All internet-facing SonicWall SMA1000 devices should be patched or taken offline until the appropriate vendor-supplied mitigations are successfully applied. Failure to act immediately significantly increases the likelihood of a successful compromise by malicious actors currently weaponizing this flaw.

More SonicWall CVEs

Sources

Originally found and disclosed by Adam Babis of SonicWall PSIRT, per the CVE Program record.