CISA added two SonicWall SMA1000 flaws to the Known Exploited Vulnerabilities catalog on the same day, September 2, 2026: CVE-2026-83548, a pre-authentication server-side request forgery issue scored CVSS 3.1 base 10.0, and CVE-2026-83549, a post-authentication OS command injection scored 7.8. Both carry a KEV listing, which CISA assigns only on evidence of real-world exploitation.
What each flaw is
CVE-2026-83548 affects the SMA1000 Appliance Work Place interface. Per NVD’s record, the root cause is an unintended alternate access path that lets a remote, unauthenticated attacker reach functionality that should sit behind authentication. NVD and CISA KEV both classify it under CWE-918 (server-side request forgery) and CWE-441 (unintended proxy or intermediary) — a pairing that describes an appliance acting as a request relay it was never meant to be.
NVD scores it CVSS 3.1 base 10.0 with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The scope change (S:C) is what pushes the score to a full 10.0: the impact does not stay inside the vulnerable component.
CVE-2026-83549 sits in a different part of the same product — the SMA1000 Appliance Management Console. NVD describes it as an OS command injection (CWE-78, agreed by NVD, CISA KEV and VulnCheck KEV) that, under specific conditions, could let an authenticated administrator run arbitrary operating-system commands, resulting in remote code execution. NVD scores it CVSS 3.1 base 7.8.
One wrinkle worth flagging rather than smoothing over: NVD’s own CVSS vector for CVE-2026-83549, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, scores the attack vector as Local, while NVD’s prose description characterises the attacker as remote and authenticated as administrator. We report both as NVD published them. This is an internal inconsistency within a single source, not a disagreement between two sources, and our source data has no second scoring body to arbitrate it.
What the evidence actually supports
| Claim | Value | Sources agreeing | Confidence |
|---|---|---|---|
| Exploitation status | KEV-listed, both CVEs | CISA KEV, VulnCheck KEV | High |
| KEV date added | 2026-09-02 | CISA KEV, VulnCheck KEV | High |
| Weakness class | CWE-918 + CWE-441 / CWE-78 | NVD, CISA KEV, VulnCheck KEV | High |
| Vendor and product | SonicWall, SMA1000 Appliances | CISA KEV, VulnCheck KEV | High |
| CVSS scores and vectors | 10.0 / 7.8 | NVD only | Medium |
| Flaw descriptions | as quoted above | NVD only | Medium |
The exploitation claim is the strongest thing on this page. The severity numbers are the weakest — single-sourced to NVD, and we saw at least one aggregator republishing CVE-2026-83548 at a lower base score than NVD assigns. We report NVD’s 10.0 because NVD is the scoring body our pipeline treats as authoritative for CVSS; a third-party site disagreeing does not change that, but readers reconciling figures across trackers should know the discrepancy exists.
Why this matters
The SMA1000 is a remote-access appliance. It exists to sit on the perimeter and terminate sessions from untrusted networks, which means a pre-authentication flaw in its Work Place interface is reachable by exactly the population it was bought to keep out. The S:C scope change in NVD’s vector is the operationally important part: the consequence is not confined to the appliance process.
The second flaw needs administrator authentication, so on its own it is a weaker primitive. What makes the pair worth treating as one remediation item is that CISA listed both on the same date against the same product line — the patching decision is a single appliance-firmware decision either way, not two separately scheduled ones. Our data does not state whether the two were observed being used together, and we are not asserting that they were.
Two comparable perimeter-appliance findings from the same KEV window put this in context. Citrix NetScaler’s CVE-2026-19490 authentication bypass reached KEV a week later, on September 9, and follows the same shape: an alternate-path weakness (CWE-288 there, CWE-441 here) in an internet-facing access gateway. Fortinet’s CVE-2025-25249 heap overflow joined KEV on the same September 9 date. Separately, the other CVE that entered KEV on this exact September 2 date and that we cover is Kestra OSS’s CVE-2026-49869 authentication-filter bypass — different technology, same batch.
Intelligence gaps
- No EPSS score. FIRST’s EPSS model has produced no score for either CVE in our ingested data. We can say CISA has exploitation evidence; we cannot attach a probability estimate to it.
- No fixed-version data in our pipeline. Neither NVD nor the KEV records we ingested carry structured affected/fixed version ranges for SMA1000 firmware. SonicWall’s own PSIRT advisory, SNWLID-2026-0016, is the reference NVD points to for version specifics.
- No per-field source URLs. Our provenance table records which source supplied each field but not a per-field link. We attribute by source name rather than construct a citation URL we do not hold.
- No attribution data. We have no threat-actor, campaign or telemetry source behind these records, so we make no claim about who is exploiting them.
Frequently Asked Questions
Is CVE-2026-83548 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 2, 2026, and CISA only adds a CVE there when it has evidence of exploitation in the wild. VulnCheck’s KEV data agrees.
How severe is CVE-2026-83548? NVD scores it CVSS 3.1 base 10.0 (critical) — network-reachable, no authentication, no user interaction, with a scope change. That figure comes from NVD alone in our data.
Does CVE-2026-83549 need credentials? Per NVD’s description, yes — it requires an attacker already authenticated as an administrator to the SMA1000 Appliance Management Console. It is scored 7.8, lower than its pre-authentication counterpart.
What should SMA1000 administrators do first? Treat the appliance firmware update as a single priority item covering both CVEs, following SonicWall’s PSIRT advisory SNWLID-2026-0016, and check the appliance’s internet exposure. CISA’s KEV entry directs organisations to vendor instructions and to CISA’s BOD 26-04 risk-based patching guidance rather than publishing its own fixed deadline.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, with corroborating KEV metadata from VulnCheck, aggregated September 17, 2026. See more vulnerability intelligence.