Vulnerability record · CVE-2026-83549 · published 1 September 2026
CVE-2026-83549: SonicWall SMA1000 AMC OS Command Injection
Sonicwall · Sma8200v
The SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary operating system commands under specific conditions. Because the affected appliance is a remote-access gateway, successful exploitation yields code execution on a security-critical edge device. The record does not state which firmware builds are fixed or affected beyond the listed product names.
Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows OS command execution on an edge security appliance and is listed in CISA KEV with a three-day federal remediation deadline, indicating active exploitation.
What it is
The SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary operating system commands under specific conditions. Because the affected appliance is a remote-access gateway, successful exploitation yields code execution on a security-critical edge device. The record does not state which firmware builds are fixed or affected beyond the listed product names.
Impact
An attacker with administrator access to the AMC gains arbitrary OS command execution on the appliance, leading to full compromise of the device and any credentials or sessions it brokers. The CVSS impact ratings for confidentiality, integrity and availability are all High.
Attack surface
The CVSS vector is AV:L/PR:L/UI:N, indicating local access with low privileges and no user interaction, though the description frames the actor as a remote authenticated administrator reaching the AMC. Either way, valid credentials are required; no unauthenticated path is described.
Exploitation
CVE-2026-83549 was added to CISA KEV on 2026-09-02 with a remediation due date of 2026-09-05, which indicates known exploitation in the wild. EPSS is 0.08505 (94.75th percentile), and no ransomware campaign use is documented.
What to do
- Apply the SonicWall vendor fix per PSIRT advisory SNWLID-2026-0016 as the first action, following CISA BOD 26-04 guidance.
- If no patch is available for a given model, discontinue use of the product or isolate the AMC from untrusted networks as CISA directs.
- Restrict and audit administrator accounts on SMA1000 appliances; remove unused admin accounts and enforce least privilege.
- Limit management interface exposure to trusted networks or a hardened jump host rather than the public internet.
- Monitor vendor and CISA guidance for updated remediation deadlines given the 2026-09-05 KEV due date.
Detection
- Hunt appliance and AMC logs for unexpected child processes or shell invocations spawned by the management console.
- Alert on anomalous administrator logins to the AMC, especially from new source IPs or outside normal maintenance windows.
- Review outbound connections and file changes on SMA1000 appliances for signs of post-exploitation activity.
- Correlate AMC admin activity with OS-level command execution telemetry where available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-83549 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "SonicWall SMA1000 Appliances OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549 | US Government Resource |
Track CVE-2026-83549 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-83549), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.