Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3540 articles · 208292 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-83548KEVEXPLOITEDPATCHED
sonicwall · sma8200v

CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Affected Products

VendorProductVersions
sonicwallsma8200v12.4.3-03453 (platform-hotfix) and older versions, 12.5.0-02835 (platform-hotfix) and older versions

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallsma6210_firmwarecve_cpe95%
sonicwallsma7210_firmwarecve_cpe95%
sonicwallsma6210cve_cpe95%
sonicwallsma7210cve_cpe95%
sonicwallsmacert_advisory90%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016(vendor-advisory)

Related News (15 articles)

Tier D
The Hacker News2h ago
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
→ No new info (linked only)
Tier D
CSO Online8h ago
SonicWall reports two major security holes under active exploit
→ No new info (linked only)
Tier D
Dark Reading11h ago
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
→ No new info (linked only)
Tier C
Rapid7 Blog15h ago
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
→ No new info (linked only)
Tier B
CCCS Canada19h ago
SonicWall security advisory (AV26-872)
→ No new info (linked only)
Tier D
Heise Security19h ago
Remotezugriff Sonicwall SMA1000: Angreifer verbiegen interne Dienste
→ No new info (linked only)
Tier D
The Hacker News21h ago
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
→ No new info (linked only)
Tier B
BSI Advisories21h ago
[NEU] [hoch] SonicWall SMA: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Help Net Security21h ago
SonicWall SMA 1000 appliances under attack via zero-day flaws
→ No new info (linked only)
Tier D
Infosecurity Magazine23h ago
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
→ No new info (linked only)
Tier D
BleepingComputer1d ago
SonicWall warns of actively exploited SMA1000 zero-day flaws
→ No new info (linked only)
Tier D
SecurityWeek1d ago
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-83548 | SonicWall SMA1000 Work Place Interface server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
CWECWE-918, CWE-441
PublishedSep 1, 2026
Trending Score169🔥
Source articles15
Independent13
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-83549EXPKEV
CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Trending: 150
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 95
HIGHCVE-2026-66153
CVE-2026-66153: The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows
Trending: 16
HIGHCVE-2026-66152
CVE-2026-66152: A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to
Trending: 16
CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 1, 2026
Added to CISA KEV
Sep 1, 2026
Discovered by ZDM
Sep 1, 2026
Actively Exploited
Sep 3, 2026
Patch Available
Sep 3, 2026