← Vulnerability feed

Vulnerability record · CVE-2026-83549 · published 1 September 2026

CVE-2026-83549: SonicWall SMA1000 AMC OS Command Injection

Sonicwall · Sma8200v

The SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary operating system commands under specific conditions. Because the affected appliance is a remote-access gateway, successful exploitation yields code execution on a security-critical edge device. The record does not state which firmware builds are fixed or affected beyond the listed product names.

7.8 CVSS 3.1 High CISA KEV since 2 Sep 2026 EPSS 11% · top 4.3% CWE-78 · OS command injection
7.8CVSS 3.1 base score
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
21 Sep 2026Last modified by NVD

Description

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityThe flaw allows OS command execution on an edge security appliance and is listed in CISA KEV with a three-day federal remediation deadline, indicating active exploitation.

What it is

The SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary operating system commands under specific conditions. Because the affected appliance is a remote-access gateway, successful exploitation yields code execution on a security-critical edge device. The record does not state which firmware builds are fixed or affected beyond the listed product names.

Impact

An attacker with administrator access to the AMC gains arbitrary OS command execution on the appliance, leading to full compromise of the device and any credentials or sessions it brokers. The CVSS impact ratings for confidentiality, integrity and availability are all High.

Attack surface

The CVSS vector is AV:L/PR:L/UI:N, indicating local access with low privileges and no user interaction, though the description frames the actor as a remote authenticated administrator reaching the AMC. Either way, valid credentials are required; no unauthenticated path is described.

Exploitation

CVE-2026-83549 was added to CISA KEV on 2026-09-02 with a remediation due date of 2026-09-05, which indicates known exploitation in the wild. EPSS is 0.08505 (94.75th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the SonicWall vendor fix per PSIRT advisory SNWLID-2026-0016 as the first action, following CISA BOD 26-04 guidance.
  • If no patch is available for a given model, discontinue use of the product or isolate the AMC from untrusted networks as CISA directs.
  • Restrict and audit administrator accounts on SMA1000 appliances; remove unused admin accounts and enforce least privilege.
  • Limit management interface exposure to trusted networks or a hardened jump host rather than the public internet.
  • Monitor vendor and CISA guidance for updated remediation deadlines given the 2026-09-05 KEV due date.

Detection

  • Hunt appliance and AMC logs for unexpected child processes or shell invocations spawned by the management console.
  • Alert on anomalous administrator logins to the AMC, especially from new source IPs or outside normal maintenance windows.
  • Review outbound connections and file changes on SMA1000 appliances for signs of post-exploitation activity.
  • Correlate AMC admin activity with OS-level command execution telemetry where available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-83549 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "SonicWall SMA1000 Appliances OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-83549 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed9.8CVE-2025-23006SonicWall SMA1000 pre-auth deserialization allows OS command executionThe SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific condition…KEVEPSS 23%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed6.6CVE-2025-40602SonicWall SMA1000 management console missing authorization privilege escalationThe SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to C…KEVEPSS 2.8%analysed7.2CVE-2026-4116Sonicwall sma6210 firmware vulnerabilityImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu…EPSS 0.71%7.2CVE-2026-4112Sonicwall sma6210 firmware sql injection vulnerabilityImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic…EPSS 0.53%7.2CVE-2026-4113Sonicwall sma6210 firmware vulnerabilityAn observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2026-83549), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.