Skip to content
COOEY

EXPOSURES › CVE-2026-83548

CVE-2026-83548

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-09-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-83548 ↗
◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 88/100 exploited-in-wildunpatchedzero-day

SonicWall SMA1000 appliances suffered an actively exploited SSRF vulnerability allowing unauthenticated remote attackers to bypass security controls and perform unauthorized operations.

A server-side request forgery (SSRF) flaw in SonicWall SMA1000 appliances was weaponized as a zero-day and actively exploited before disclosure, enabling attackers to access sensitive functionality without authentication. This exposes organizations to data theft, lateral movement, and potential ransomware deployment, directly impacting CMMC/NIST 800-171 compliance by violating access control and system integrity requirements. DIB organizations must immediately patch affected appliances and assess exposure to similar unpatched, exploited-in-wild vulnerabilities in their supply chain.

Shame score — A maximum-severity SSRF vulnerability was weaponized as a zero-day and actively exploited in the wild before disclosure, demonstrating severe negligence in patch management and security engineering.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.