{"cve":{"cve_id":"CVE-2026-83548","is_kev":true,"kev_date_added":"2026-09-02","kev_vendor_project":"SonicWall","kev_product":"SMA1000 Appliances","kev_vulnerability_name":"SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability","kev_short_description":"SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.","kev_required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due_date":"2026-09-05","kev_known_ransomware":false,"kev_notes":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548","kev_cwes":["CWE-918","CWE-441"],"epss_score":0.04667,"epss_percentile":0.91256,"epss_as_of":"2026-09-15","description":"A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.","published_at":"2026-09-01T21:25:45.368000Z","last_modified_at":"2026-09-03T13:06:16.053000Z","cvss_v3_score":10.0,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":["CWE-918","CWE-441"],"nvd_references":["https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":true,"trended_number_one":false,"trending_peak_score":0.5823402536006023,"trending_peak_rank":2,"started_trending_at":"2026-09-09T05:39:24.669179Z","trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-09-01T22:34:30.376202Z","updated_at":"2026-09-09T18:41:04.697795Z"},"effective_severity":"CRITICAL","badges":["kev","poc","news"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"C","value_label":"Changed"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"sonicwall","vendor_name":"SonicWall","product_slug":"sma1000","product_name":"SMA1000","version_start":"12.4.3-03453 (platform-hotfix) and older versions","version_start_inclusive":true,"version_end":"12.4.3-03453 (platform-hotfix) and older versions","version_end_inclusive":true,"cpe23_uri":"cve5:sonicwall:sma1000:12.4.3-03453 (platform-hotfix) and older versions:12.4.3-03453 (platform-hotfix) and older versions"},{"vendor_slug":"sonicwall","vendor_name":"SonicWall","product_slug":"sma1000","product_name":"SMA1000","version_start":"12.5.0-02835 (platform-hotfix) and older versions","version_start_inclusive":true,"version_end":"12.5.0-02835 (platform-hotfix) and older versions","version_end_inclusive":true,"cpe23_uri":"cve5:sonicwall:sma1000:12.5.0-02835 (platform-hotfix) and older versions:12.5.0-02835 (platform-hotfix) and older versions"},{"vendor_slug":"sonicwall","vendor_name":"SonicWall","product_slug":"sma6210-firmware","product_name":"sma6210_firmware","version_start":null,"version_start_inclusive":null,"version_end":"12.4.3-03526","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*"},{"vendor_slug":"sonicwall","vendor_name":"SonicWall","product_slug":"sma7210-firmware","product_name":"sma7210_firmware","version_start":null,"version_start_inclusive":null,"version_end":"12.4.3-03526","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*"},{"vendor_slug":"sonicwall","vendor_name":"SonicWall","product_slug":"sma8200v","product_name":"sma8200v","version_start":null,"version_start_inclusive":null,"version_end":"12.4.3-03526","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*"}],"exploit_refs":[{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2026/CVE-2026-83548.yaml","title":"SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB","author":"rapid7,DhiyaneshDk","disclosed_at":null}],"news":[{"id":1660,"source":"The Hacker News","url":"https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html","title":"CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs.\n\nThe vulnerabilities are as follows -\n\n\n  CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaGEC2JQn3dU5muXzZhp9ouduHJ5hE4vWW4zHDomXp7hJ3hHafGPmMU33aKs7A8dwhvqsMiwh8PNi4GUNzH635enPZT3oPdcZejqkA9vpPYbQTLZaAhzAVAuUFksC4mCNX6SRUzUx1vhSxokKBz9RBGXXOBJshSXfYLIox2OCi2htQdcmyDJDMvWTamC8/s1600/cisa.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-09-03T05:19:04Z","fetched_at":"2026-09-03T07:17:30.829212Z","trending_score":0.0029496627087216665,"cve_ids":["CVE-2026-83548"]},{"id":1640,"source":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html","title":"Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain","summary":"SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.\n\nThe vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below -\n\n\n  CVE-2026-83548 (CVSS score: 10.0) -&nbsp; A pre-authentication SSRF vulnerability in the Appliance","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHkRZMEpG9dgsbvSzYfaPZC5u0gmzUw-5NHDTcsQ-MQtxr6pqNrngG2LsyMJ0KKxA364L3Lq4xhGAxCTRQ3C8szlo9aLJeWXw37C6hsAD5YbYCJF8KuQyuWMIPNCNDXX8-1HN76xxYhxffeenDDyWobOpA4AXC76hFcdh1vnqpjI_pLF2YuxiAwu87cHwC/s1600/sonicwall.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-09-02T10:53:49Z","fetched_at":"2026-09-02T11:02:30.728793Z","trending_score":0.0022607204901814674,"cve_ids":["CVE-2026-83548"]}],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016","source_type":"VENDOR_ADVISORY","tags":["advisory"]}],"timeline":[{"type":"published","at":"2026-09-01T21:25:45.368000Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2026-09-02T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"first_article","at":"2026-09-02T10:53:49Z","label":"First news coverage","source":"The Hacker News"},{"type":"ssvc_changed","at":"2026-09-02T14:35:30.377640Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-09-02T14:35:30.377640Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-09-02T14:35:30.377640Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-09-02T14:35:30.377640Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-09-02T14:35:30.377640Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-09-02T14:35:30.377640Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-09-03T05:35:30.381744Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"poc_available","at":"2026-09-09T05:36:54.198990Z","label":"Public PoC available","source":"nuclei"},{"type":"started_trending","at":"2026-09-09T05:39:24.669179Z","label":"Started trending","source":null}]}