Knox CVE Database
/
CVE-2026-83548
Critical
10.0

CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Added to the CISA KEV catalog:
September 2, 2026

Overview

SonicWall SMA1000 appliances running firmware versions up to and including 12.4.3-03453 and 12.5.0-02835 contain a pre-authentication server-side request forgery flaw in the Work Place interface. The interface acts as an unintended forward proxy, allowing a remote unauthenticated attacker to send crafted requests that the appliance forwards to internal or sensitive backend resources. This gives the attacker access to functionality and the ability to perform operations that should require authentication, with potential full impact on confidentiality, integrity, and availability of reachable systems. SonicWall PSIRT has confirmed active exploitation.

Vulnerability details

Affected vendor
SonicWall
Affected product
SMA1000 Appliances
Weakness type (CWE)
CWE-918, CWE-441

The Work Place interface on SMA1000 appliances contains an unintended alternate access path that causes the appliance to act as a forward proxy for attacker-controlled requests. In a server-side request forgery flaw (CWE-918), the vulnerable server accepts a request from an external party and then makes a secondary request to an internal or otherwise restricted resource on the attacker's behalf. The confused deputy aspect (CWE-441) means the appliance carries the trust of an internal network participant, forwarding requests to backend systems that would otherwise be unreachable from the internet, all without requiring any credential from the attacker.


An attacker sends a crafted HTTP request to the publicly exposed Work Place interface with attacker-controlled target parameters. The appliance, acting as an unintended proxy, forwards that request to internal resources using its own privileged network position. No authentication is required at any stage. The attacker gains access to sensitive internal functionality and can perform unauthorized operations against systems reachable by the SMA1000, with the scope extending beyond the appliance itself to downstream infrastructure. SonicWall has confirmed this vulnerability is being actively exploited in the wild.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review SMA1000 Work Place interface access logs for requests from unexpected external sources that target internal hostnames, RFC-1918 addresses, or loopback addresses as destination parameters, which would indicate SSRF probing or exploitation.
  • Check for indicators of compromise as directed by SonicWall PSIRT: the vendor advisory explicitly recommends contacting SonicWall Technical Support for IoC review, and instructs operators to re-image or redeploy appliances and reset all credentials if IoCs are found.
  • Monitor for anomalous outbound connections originating from the SMA1000 appliance itself to internal network segments or services that the appliance would not normally contact during legitimate operation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 5, 2026

Additional hardening

  • Upgrade SMA1000 models 6210, 7210, and 8200v to firmware 12.4.3-03526 or 12.5.0-02952 (platform-hotfix), the fixed releases identified in the vendor advisory. No workaround is available; patching is the only remediation.
  • Restrict internet exposure of the Work Place interface to the minimum necessary set of source addresses using perimeter firewall rules or access control lists, reducing the attack surface while patching is staged.
  • If IoCs are detected on an affected appliance, re-image hardware units or redeploy virtual instances, then rotate all user and administrator passwords and reset all TOTP tokens before returning the appliance to service.
  • Segment the SMA1000 from sensitive internal systems it does not need to reach directly, limiting the blast radius of any SSRF exploitation by constraining which backend resources the appliance can proxy requests to.

Key dates

Published (NVD)
September 1, 2026
Added to CISA KEV
September 2, 2026
Remediation deadline
September 5, 2026
Last updated
September 3, 2026

References

Frequently asked questions

Does CVE-2026-83548 affect my FedRAMP authorization?

If SonicWall SMA1000 Appliances runs inside your authorization boundary, CVE-2026-83548 affects your FedRAMP authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its September 5, 2026 remediation deadline has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. Your path forward is either remediation now or formal documentation of the mitigation and the delay.

How does Knox help me handle CVE-2026-83548?

Knox does not patch your software. Remediating SonicWall SMA1000 Appliances is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including cases like CVE-2026-83548. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you earlier visibility and more time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-83548's remediation deadline of September 5, 2026 has passed. What happens now?

An unremediated CVE-2026-83548 is now a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Closing out the finding and formally documenting why the deadline was missed is what keeps your authorization intact and your agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting