SonicWall SMA1000 flaws exploited before disclosure
SonicWall disclosed two vulnerabilities in its SMA1000 secure mobile access appliances: an unauthenticated SSRF in the WorkPlace portal rated CVSS 10.0 and an OS command injection in the management console rated CVSS 7.8. Both were exploited before public disclosure, and CISA added them to its Known Exploited Vulnerabilities catalog on September 2, 2026.
- CVE-2026-83548: unauthenticated SSRF in WorkPlace, CVSS 10.0
- CVE-2026-83549: command injection in console, CVSS 7.8
- Affected: SMA 6210, SMA 7210 and SMA 8200v virtual appliance
- CISA added both to its KEV catalog on September 2, 2026
Read next
Security