EXPOSURES › CVE-2026-83548
CVE-2026-83548
HIGH ⌖ ON CISA KEV · EXPLOITEDSonicWall SMA1000 appliances suffered an actively exploited SSRF vulnerability allowing unauthenticated remote attackers to bypass security controls and perform unauthorized operations.
A server-side request forgery (SSRF) flaw in SonicWall SMA1000 appliances was weaponized as a zero-day and actively exploited before disclosure, enabling attackers to access sensitive functionality without authentication. This exposes organizations to data theft, lateral movement, and potential ransomware deployment, directly impacting CMMC/NIST 800-171 compliance by violating access control and system integrity requirements. DIB organizations must immediately patch affected appliances and assess exposure to similar unpatched, exploited-in-wild vulnerabilities in their supply chain.
Shame score — A maximum-severity SSRF vulnerability was weaponized as a zero-day and actively exploited in the wild before disclosure, demonstrating severe negligence in patch management and security engineering.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.