CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2026-09-02. EPSS: 8% chance of exploitation in the next 30 days.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Affected products
- SonicWall SMA6210 Firmware: before 12.4.3-03526 (fixed in 12.4.3-03526); from 12.5.0, before 12.5.0-02952 (fixed in 12.5.0-02952)
- SonicWall SMA7210 Firmware: before 12.4.3-03526 (fixed in 12.4.3-03526); from 12.5.0, before 12.5.0-02952 (fixed in 12.5.0-02952)
- SonicWall SMA8200V: before 12.4.3-03526 (fixed in 12.4.3-03526); from 12.5.0, before 12.5.0-02952 (fixed in 12.5.0-02952)
Published 2026-09-01. Last modified 2026-09-03.