CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in the SonicWall SMA1000 Appliance WorkPlace interface, caused by an unintended alternate access path. The interface can proxy unauthenticated HTTP OPTIONS requests to an internal loopback CouchDB service, bypassing authentication and exposing sensitive functionality to unauthorized operations. Affected products include SMA1000 models 6210, 7210, and 8200v running platform-hotfix versions 12.4.3-03453 and earlier or 12.5.0-02835 and earlier. The vulnerability was actively exploited before its September 1, 2026 disclosure. Attackers have chained it with CVE-2026-83549 to achieve unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 4 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
176 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SonicWall SMA1000 zero-day chained with CVE-2026-83549 in September 2026 attacks to achieve remote code execution. The article does not specify its individual technical mechanism.
An earlier pre-authentication vulnerability affecting the SonicWall SMA1000 WorkPlace interface, cited as historical context because it was exploited as a zero-day. The content does not provide further technical details.
A previously patched CVSS 10.0 pre-authentication SSRF zero-day in SonicWall SMA1000 VPN appliances, mentioned as historical context. SonicWall confirmed exploitation in the wild, with attackers likely chaining it with CVE-2026-83549 to achieve arbitrary code execution.
One of two previously exploited SMA1000 vulnerabilities disclosed September 1. The pair comprised a CVSS 10.0 unauthenticated WorkPlace SSRF flaw and an authenticated administrator command-execution flaw; the content does not explicitly map those descriptions to the individual CVE IDs. Fixes were provided in platform-hotfix versions 12.4.3-03526 and 12.5.0-02952. Mentioned as historical comparison. Compromise checks and conditional appliance recovery, password changes, and TOTP token resets were recommended.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.