What We Know
TrendingJust now

SonicWall SMA1000 flaws include pre-authentication SSRF and exploited RCE chain

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Trending

What We Know

The vulnerability is a pre-authentication server-side request forgery flaw in the SMA1000 Appliance Work Place interface, attributed to an unintended alternate access path that may expose sensitive functionality to a remote unauthenticated attacker.Backed by 1 sourcestenable.com

Security reporting says CVE-2026-83548 can be chained with CVE-2026-83549 to achieve unauthenticated remote code execution, and SonicWall has warned that the vulnerabilities are being exploited in attacks.Backed by 1 sourcessecurityweek.com

Reporting highlights exposure of internet-facing SMA1000 appliances, including 400 appliances exposed to unauthenticated RCE.Context from one sourcedecryptiondigest.com Independent security reporting describes the SMA1000 vulnerabilities as exploited in the wild or in active exploitation.Context supported by 2 independent sourcessophos.comrapid7.com

Source Comparison

Aligned reporting
2 corroborates - 3 adds context - 0 conflicts