CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Multiple vulnerabilities in SonicWall Secure Mobile Access (02 September 2026)

unknownknown exploitedCVE-2026-83548
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
On 01 September 2026, SonicWall published a security advisory concerning two vulnerabilities affecting Secure Mobile Access (SMA) 1000. The critical vulnerability CVE-2026-83548 allows server-side request forgery (SSRF) by an unauthenticated attacker. The vulnerability...

CSIRTS triage

What
An unauthenticated attacker can exploit server-side request forgery (SSRF) in Secure Mobile Access 1000.
Who is affected
Unauthenticated attackers can exploit exposed Secure Mobile Access 1000 deployments.
Urgency
Critical urgency because the vulnerability is unauthenticated and allows SSRF exploitation.
Action
Apply the SonicWall security patch for CVE-2026-83548 immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Secure Mobile Access 1000

Get an email when a new Secure Mobile Access 1000 advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-FR Alertes de sécurité (FR · national-cert · site)
Severity
unknown
Published
2026-09-02
Exploitation
Observed in the wild (CISA KEV)
Language
Machine-translated to English — verify against the original

Original advisory: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-009/

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-83548coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for SonicWall Secure Mobile

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-FR Alertes de sécurité