Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3743 articles · 207648 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-83548KEVEXPLOITEDPATCHED
sonicwall · sma1000

CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Affected Products

VendorProductVersions
sonicwallsma100012.4.3-03453 (platform-hotfix) and older versions, 12.5.0-02835 (platform-hotfix) and older versions

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016(vendor-advisory)

Related News (4 articles)

Tier D
Infosecurity Magazine1h ago
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
→ No new info (linked only)
Tier D
BleepingComputer3h ago
SonicWall warns of actively exploited SMA1000 zero-day flaws
→ No new info (linked only)
Tier D
SecurityWeek5h ago
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
→ No new info (linked only)
Tier C
VulDB12h ago
CVE-2026-83548 | SonicWall SMA1000 Work Place Interface server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
CWECWE-918, CWE-441
PublishedSep 1, 2026
Trending Score123🔥
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-83549EXPKEV
CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Trending: 120
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 107
HIGHCVE-2026-66152
CVE-2026-66152: A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to
Trending: 17
HIGHCVE-2026-66153
CVE-2026-66153: The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows
Trending: 17
CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 1, 2026
Added to CISA KEV
Sep 1, 2026
Discovered by ZDM
Sep 1, 2026
Actively Exploited
Sep 2, 2026
Patch Available
Sep 2, 2026