Critical Actively exploited
CVE-2026-83548
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
What this means
- Weakness
- The server issues a request to an attacker-chosen address, reaching into the internal network (SSRF).
- Likelihood
- Exploitation is not hypothetical: CISA has observed it in the wild.
What to doTop priority: CISA sets the remediation deadline at 5 September 2026.
Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.