The US Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active attacks against internet-facing infrastructure, including VPN gateways and AI-related platforms.[15][9] The move, reflected in CISA’s advisory stream and independent KEV-tracking dashboards, tightens remediation deadlines for federal agencies under Binding Operational Directive 26‑04 and effectively sets the patching pace for many private-sector defenders as well.[9][6][1]
Among the most serious issues highlighted in this wave of activity is CVE-2026-83548, a pre‑authentication server‑side request forgery (SSRF) flaw in SonicWall SMA 1000 secure remote access appliances that carries a maximum‑severity CVSS v3.1 base score of 10.0.[7][11][14] The bug resides in the Appliance Work Place interface, where an unintended alternate access path allows the device to act as a forward proxy and relay attacker‑controlled requests to internal or external services without any authentication.[3][14][8] SonicWall’s own advisory warns that a remote unauthenticated attacker could exploit the SSRF to gain unauthorized access to sensitive functionality and perform unauthorized operations through the appliance.[7][11][14]
The SMA 1000 series flaw affects both physical and virtual models 6210, 7210, and 8200v running specific platform hotfix builds, particularly firmware versions 12.4.3‑03453 and 12.5.0‑02835 and earlier, across supported hypervisors.[7][3][8] SonicWall and multiple security vendors report that attackers have been chaining CVE‑2026‑83548 with a second bug in the same product line, CVE‑2026‑83549, to achieve unauthenticated remote code execution on these VPN gateways.[12][10][13] Importantly, the attacks and patches discussed do not apply to SonicWall SMA 100 appliances or the company’s firewalls, narrowing the immediate exposure but leaving high‑value remote access infrastructure squarely in the crosshairs.[10][7][13]
Public reporting indicates that exploitation of the SonicWall SMA 1000 flaws has moved beyond proof‑of‑concept into real‑world campaigns, where compromised appliances serve as beachheads for further intrusion activity.[10][12][13] By abusing the SSRF condition to pivot through the gateway and then leveraging the chained remote code execution, threat actors can run arbitrary code on a device that often sits at the edge of corporate and government networks, enabling them to move laterally, harvest credentials, or deploy additional malware with few obvious user‑visible signs.[12][14][11] These tactics mirror patterns seen around other recent KEV additions, where attackers focus on exposed management interfaces and infrastructure services that offer both privileged access and operational stealth.[9][6][15]
While CISA’s KEV catalog interface has not yet publicly listed CVE‑2026‑83548 by ID, SonicWall’s advisory and multiple vulnerability trackers treat the SMA 1000 SSRF flaw as an actively exploited zero‑day now covered by the agency’s Sept. 2 exploited‑vulnerabilities notice.[1][7][9] SonicWall has released fixed firmware, recommending customers upgrade affected appliances to hotfix builds 12.4.3‑03526 or 12.5.0‑02952, which address CVE‑2026‑83548 and associated issues, and urges organizations to deploy these updates as soon as operationally feasible.[7][8][3] KEV monitoring sites note that, once individual CVEs are fully reflected in the catalog, federal civilian agencies will face aggressive patch deadlines, with other organizations likely to follow suit as those dates become de‑facto industry benchmarks.[6][9][1]
For defenders, the SonicWall SMA 1000 activity and CISA’s seven‑CVE update underline the need to treat exploited vulnerabilities in edge infrastructure as incident‑response priorities rather than routine maintenance.[9][10][15] Organizations should inventory all SMA 1000 deployments, confirm firmware levels, and expedite upgrades to the latest recommended builds while also reviewing VPN gateway logs and telemetry for evidence of anomalous proxying or command execution.[7][14][11] As KEV entries continue to skew toward remote management, VPN, and AI‑adjacent services, maintaining visibility into these systems and aligning patch cycles with CISA’s catalog updates is becoming a central plank of modern vulnerability management programs.[1][6][9]
References
- Known Exploited Vulnerabilities Catalog
- CVE-2026-83548 – Pre-Auth SSRF (Chained to RCE) – IONIX
- CISA KEV Tracker: Exploited CVEs and Deadlines
- SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026 …
- CVE-2026-83548: Server-Side Request Forgery (SSRF) | CVETodo
- CISA KEV Adds 12 CVEs as BOD 26-04 Cuts Deadline [2026]
- SonicWall SMA 1000 appliances under attack via zero-day flaws
- SonicWall SMA1000 vulnerabilities (CVE-2026-83548 … – Sophos
- CVE-2026-83548 – Exploits & Severity
- SonicWall advises customers to patch two new SMA1000 …
- CVE-2026-83548: SonicWall SMA1000: A Pre-authentication SSRF …
- Three-of-Seven CISA KEV Additions Now Target AI Infrastructure
