SonicWall SMA 1000 remains critical edge exposure after September KEV additions
CISA added SSRF CVE-2026-83548 (CVSS 10.0) and command injection CVE-2026-83549 (CVSS 7.8) in SonicWall SMA 1000 to its exploited vulnerabilities catalog on September 2, 2026, with a September 5 remediation deadline. Fixes were released in builds 12.4.3-03526 and 12.5.0-02952, while only 7 such devices are visible online.
- CVE-2026-83548 is pre-auth SSRF with CVSS 10.0
- CVE-2026-83549 is command injection in Admin Console, CVSS 7.8
- Fixed builds: 12.4.3-03526 and 12.5.0-02952
- ZoomEye found only 7 exposed SMA 1000 online
Read next
Security