Thursday , September 24 2026
VPN

SonicWall SMA1000 SSRF Hits 10, Exploiting CVE-2026-83548 

SonicWall unveiled advisory SNWLID-2026-0016 on September 1, 2026. It states that two SMA1000 flaws are being actively exploited. The main issue, CVE-2026-83548, is a pre-authentication SSRF with a top score of 10.0 CVSS. The second issue, CVE-2026-83549, allows remote code execution after authentication.

Why It Matters
SMA1000 devices act as VPN gateways for businesses. Because of this, a security weakness lets remote attackers access them easily. This SonicWall SMA1000 flaw doesn’t require any login details or user action.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

A successful attacker gets to features that should not be seen. From there, the second problem can allow access to running code. SonicWall says both are already being attacked.

How the Attack Works
CVE-2026-83548 is found in the SMA1000 Work Place system. The notice calls it an SSRF because of an unexpected access path. This means the device works like an accidental forward proxy.

A remote attacker can access sensitive functions without needing to log in. The warning says they might “do things without permission.” The second issue, CVE-2026-83549, lets an admin use command injection in the Management Console. This means the admin can run any commands they want. The report does not share details on how to exploit it.

CVE CVSS (CVSSv3) Type Status
CVE-2026-83549 7.8 CWE-78 Exploited in the wild
CVE-2026-83548 Awaiting analysis CWE-441 Exploited in the wild

Exploitation Status
SonicWall says this SonicWall SMA1000 problem is being actively used by attackers. Its PSIRT looked into a situation that showed real attacks happening. This is similar to a July 2026 SMA1000 event, where attackers combined a similar pre-auth SSRF with a bug that allowed code to run.

Affected Versions
The flaws affect SMA1000 models 6210, 7210, and 8200v. At-risk versions include 12.4.3-03453 and older, as well as 12.5.0-02835 and older. The issues do not affect SMA 100 Series devices or firewall SSL-VPN.

Patch and Mitigation Steps
No workaround exists, so patching is the only fix. Upgrade to 12.4.3-03526 or 12.5.0-02952, or later, from mysonicwall.com.

Check Also

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could …