CISA adds two SonicWall SMA1000 flaws to exploited vulnerabilities catalog
CISA added two SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of 5 September 2026. Chained, a pre-auth SSRF rated 10.0 and an OS command injection rated 7.8 let an unauthenticated attacker reach root-level code execution.
- CISA added CVE-2026-83548 and CVE-2026-83549 to KEV on 2 September 2026
- Pre-auth SSRF rated 10.0, admin console command injection rated 7.8
- Fixed firmware versions: 12.4.3-03526 and 12.5.0-02952
- Affected models: SMA1000 6210, 7210 and 8200v
Read next
Security