What We Know
The vulnerability is a pre-authentication server-side request forgery flaw in the SMA1000 Appliance Work Place interface, attributed to an unintended alternate access path that may expose sensitive functionality to a remote unauthenticated attacker.1Backed by 1 sourcestenable.com
Security reporting says CVE-2026-83548 can be chained with CVE-2026-83549 to achieve unauthenticated remote code execution, and SonicWall has warned that the vulnerabilities are being exploited in attacks.1Backed by 1 sourcessecurityweek.com
Reporting highlights exposure of internet-facing SMA1000 appliances, including 400 appliances exposed to unauthenticated RCE.1Context from one sourcedecryptiondigest.com Independent security reporting describes the SMA1000 vulnerabilities as exploited in the wild or in active exploitation.2Context supported by 2 independent sourcessophos.comrapid7.com
Source Comparison
Aligned reportingCorroborates
- securityweek.com↗Reports that CVE-2026-83548 and CVE-2026-83549 can be chained for unauthenticated remote code execution and describes the flaws as exploited zero-days.
- tenable.com↗Matches the technical description of a pre-authentication SSRF flaw caused by an unintended alternate access path that could expose sensitive functionality to a remote unauthenticated attacker.
Adds context
- decryptiondigest.com↗Highlights the exposure risk for internet-facing SMA1000 appliances and reports that 400 appliances were exposed to unauthenticated RCE.
- sophos.com↗Identifies both SMA1000 vulnerabilities as being in active exploitation and dates the reporting to September 1 and 2, but the excerpt does not establish the assigning organization.
- rapid7.com↗Reports that both critical SMA1000 vulnerabilities were exploited in the wild and places the reporting on September 2, 2026.