SonicWall shipped another SMA1000 SSRF and another command injection. CISA gave the last pair a three-day deadline in July
2026-09-03Security
CVE-2026-83548 is a pre-auth SSRF with a CVSS of 10.0; CVE-2026-83549 is post-auth command execution as administrator. That is the same two bug classes, in the same auth positions, on the same appliance that CISA added to KEV seven weeks ago — and both rounds are being exploited.