A critical pre-authentication SSRF vulnerability in SonicWall SMA1000 appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-83548, in SonicWall SMA1000 appliances was exploited on the same day it was publicly disclosed. The vulnerability, which affects the WorkPlace interface of SMA1000 appliances, allows a remote, unauthenticated attacker to potentially gain unauthorized access to sensitive functionalities and perform unauthorized operations.
SonicWall confirmed the vulnerability, detailing it as a pre-authentication SSRF flaw stemming from an unintended alternate access path. The company assigned the vulnerability a CVSS score of 10, indicating critical severity, and published its own security advisory, SNWLID-2026-0016, on September 1, 2026.
The United States Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026, just one day after its public disclosure. CISA's directive, BOD 26-04, mandates federal agencies to apply mitigations for such vulnerabilities by September 5, 2026. The European Union Agency for Cybersecurity (ENISA) also listed the vulnerability in its KEV catalog on September 2, 2026.
Evidence of active exploitation was reported as early as September 1, 2026, coinciding with the CVE's publication. Multiple sources, including commercial cybersecurity research firms and public security bulletins, corroborated the immediate exploitation. The earliest confirmed listing of the vulnerability as "exploited in the wild" appeared on September 1, 2026, in a commercial research KEV catalog.
The vulnerability's weakness is categorized under CWE-441, which refers to "Insufficiency of Protection Against Server-Side Request Forgery." The Exploit Prediction Scoring System (EPSS) for CVE-2026-83548 is 0.71%, placing it in the 50.8th percentile, suggesting a moderate likelihood of exploitation.
Organizations using SonicWall SMA1000 appliances are urged to apply vendor-provided mitigations immediately. CISA's guidance also advises evaluating each asset's internet exposure and adhering to patching guidelines, or discontinuing use of the product if mitigations are unavailable.

CVE-2026-81578, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-82078, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

A critical OS command injection vulnerability in SonicWall SMA1000 Appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

A critical authentication vulnerability in JFrog Artifactory was exploited on the same day its CVE was published, leaving no patch window for users. The flaw allows unauthenticated attackers to gain administrative privileges.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.