๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Summary
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability (SSRF, a bug where an attacker tricks a server into making unauthorized requests on their behalf) that allows unauthenticated remote attackers to access sensitive features and perform unauthorized operations. This vulnerability is actively being exploited by real attackers. Organizations must apply vendor-provided mitigations by September 5, 2026, following CISA's BOD 26-04 guidance on prioritizing security updates.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines. See vendor details at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
September 1, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-83548
First tracked: September 2, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%