{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asonicwallsma1000_appliances/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sonicwall:sma1000_appliances:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-83548"},{"cvss":7.8,"id":"CVE-2026-83549"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SMA1000 Appliances"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","ssrf","network-appliance"],"_cs_type":"advisory","_cs_vendors":["SonicWall"],"content_html":"\u003cp\u003eSonicWall has disclosed a critical server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-83548, affecting SMA1000 series appliances. This vulnerability allows an unauthenticated remote attacker to bypass security controls by coercing the appliance into making unintended internal network requests. By leveraging this SSRF, an adversary can access administrative interfaces, internal services, or sensitive metadata not intended for public access, potentially leading to unauthorized configuration changes or further exploitation of the internal network. Given the appliance's role as a secure access gateway, successful exploitation provides a strategic foothold within the organization's perimeter. This vulnerability has been included in CISA’s Known Exploited Vulnerabilities (KEV) catalog, mandating remediation for federal agencies and high-risk environments under BOD 26-04. Defenders should prioritize auditing the exposure of these appliances and applying vendor-supplied security updates immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-83548 allows remote, unauthenticated actors to bypass authentication and interact with internal-only services or APIs hosted on the SMA1000 appliance. This can lead to unauthorized access to system configuration, potential remote code execution via chained internal vulnerabilities, or information disclosure regarding the internal network topography. The scope of impact includes all organizations utilizing SMA1000 appliances in an internet-facing capacity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply security patches or mitigations provided in the SonicWall PSIRT advisory SNWLID-2026-0016 immediately.\u003c/li\u003e\n\u003cli\u003eAudit internet-facing SMA1000 appliances to ensure they are compliant with CISA BOD 26-04 patching requirements.\u003c/li\u003e\n\u003cli\u003eImplement stricter egress filtering on the appliance to limit its ability to reach sensitive internal management endpoints if patching is delayed.\u003c/li\u003e\n\u003cli\u003eReview logs for anomalous HTTP requests targeting internal management URIs or non-standard backend service ports originated from the appliance.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T18:00:06Z","date_published":"2026-09-02T17:56:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma1000-ssrf/","summary":"SonicWall SMA1000 appliances are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw, enabling remote attackers to access sensitive internal functionality and perform unauthorized operations.","title":"Critical SSRF Vulnerability in SonicWall SMA1000 Appliances","url":"https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma1000-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sonicwall:sma1000_appliances:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}