CVE-2026-83548KEV · OVERDUECWE-441CWE-918ssrf

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

Critical · published September 2, 2026

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 10.0. It is confirmed in active exploitation. It sits in the 51.2th percentile for exploit probability.

2
days past CISA
deadline
CVSS v3.1
10.0
EPSS
1%
Percentile
51.2
In the wild
Confirmed
What it is

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00710 · 51.2th percentile
Weaknesses
CWE-441 · Unintended Proxy or Intermediary ('Confused Deputy'); CWE-918 · Server-Side Request Forgery (SSRF)
Published
2026-09-02T02:17Z
KEV added
2026-09-02 · due 2026-09-05
Affected products (6)
ProductVersionsFixed in
sonicwall/sma8200v< 12.4.3-0352612.4.3-03526
sonicwall/sma8200v≥ 12.5.0, < 12.5.0-0295212.5.0-02952
sonicwall/sma6210_firmware< 12.4.3-0352612.4.3-03526
sonicwall/sma6210_firmware≥ 12.5.0, < 12.5.0-0295212.5.0-02952
sonicwall/sma7210_firmware< 12.4.3-0352612.4.3-03526
sonicwall/sma7210_firmware≥ 12.5.0, < 12.5.0-0295212.5.0-02952
References (2)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 02 SEP 00:00Z
    Added to CISA KEV — remediate by Sep 5
    kev
  • 01 SEP 21:25Z
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path
    cvelistv5