Apply the latest firmware/software updates for SMA 1000 series appliances immediately via SonicWall's support portal. Monitor SonicWall advisories for additional guidance. Segregate SMA appliances from untrusted networks where possible.
Quick answers
What is CVE-2026-83548?
Apply the latest firmware/software updates for SMA 1000 series appliances immediately via SonicWall's support portal. Monitor SonicWall advisories for additional guidance. Segregate SMA appliances from untrusted networks where possible.
How severe is CVE-2026-83548?
critical, CVSS 10
Is CVE-2026-83548 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-83548 be mitigated?
Apply the latest firmware/software updates for SMA 1000 series appliances immediately via SonicWall's support portal. Monitor SonicWall advisories for additional guidance. Segregate SMA appliances from untrusted networks where possible.
CVSS
10
Vendor
SonicWall
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
SMA 1000 series
Mitigation
Apply the latest firmware/software updates for SMA 1000 series appliances immediately via SonicWall's support portal. Monitor SonicWall advisories for additional guidance. Segregate SMA appliances from untrusted networks where possible.
The Cybersecurity and Infrastructure Security Agency (CISA) has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The additions span multiple vendors and technologies, including Sangoma Switchvox, Kludex Starlette, Kestra OSS, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. CISA emphasized that these flaws represent frequent attack vectors for malicious actors targeting federal and critical infrastructure systems.
SonicWall has released emergency security updates to address two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series VPN appliances. The flaws, CVE-2026-83548 and CVE-2026-83549, are being actively exploited in the wild. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability with a CVSS score of 10.0. The vulnerabilities may be chained together to enable remote code execution or unauthorized access. SonicWall researchers William Perry and Adam Babis discovered the issues internally. Patches are available via SonicWall's support portal.