peter bassill · operator
$ cve CVE-2026-83548 JSON

CVE-2026-83548 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 8.8% (pctl 95)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-05.

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS8.76% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-441
On CISA KEVyes — remediate by 2026-09-05
Public exploitnone known
Published2026-09-01
Last modified2026-09-03

CISA KEV

NameSonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Added2026-09-02
Due2026-09-05
Vendor / productSonicWall / SMA1000 Appliances
Ransomware usenone reported

Affected (5)

VendorProduct
sonicwallsma6210
sonicwallsma6210 firmware
sonicwallsma7210
sonicwallsma7210 firmware
sonicwallsma8200v

References

→ the Explorer  ·  watch your stack  ·  NVD