CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in the SonicWall SMA1000 Appliance Work Place interface. An unintended alternate access path acts as a forward proxy, allowing a remote unauthenticated requester to cause access to functionality that should not be available through that path. It affects SMA1000 6210, 7210, and 8200v appliances running 12.4.3-03453 (platform hotfix) or earlier, or 12.5.0-02835 (platform hotfix) or earlier. The vulnerability is also associated with CWE-441, Unintended Proxy or Intermediary (Confused Deputy).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A maximum-severity (CVSS 10.0) pre-authentication SSRF vulnerability caused by an unintended alternate access path in the SonicWall SMA1000 Appliance Work Place interface. It may allow a remote unauthenticated attacker to access sensitive functionality and conduct unauthorized operations.
A maximum-severity SMA1000 Appliance WorkPlace command-injection vulnerability, arising from an SSRF weakness, that attackers are actively chaining with CVE-2026-83549 to achieve remote code execution.
A maximum-severity SMA1000 Appliance WorkPlace command-injection vulnerability, stemming from SSRF, that is being chained in remote-code-execution attacks.
A critical, pre-authentication server-side request forgery vulnerability in the Appliance Work Place interface of SonicWall SMA1000 secure remote-access gateway and SSL-VPN appliances. It can provide unauthenticated access to sensitive functionality and was observed exploited in the wild, apparently chained with CVE-2026-83549 for remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.