CVE-2026-83549 KEV
7.8
HIGH · CVSS 3.1 · EPSS 10.8% (pctl 96)
Patch first
On CISA KEV — known exploited in the wild, due 2026-09-05.
Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 10.76% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2026-09-05 |
| Public exploit | none known |
| Published | 2026-09-01 |
| Last modified | 2026-09-21 |
CISA KEV
| Name | SonicWall SMA1000 Appliances OS Command Injection Vulnerability |
|---|---|
| Added | 2026-09-02 |
| Due | 2026-09-05 |
| Vendor / product | SonicWall / SMA1000 Appliances |
| Ransomware use | none reported |
Affected (5)
| Vendor | Product |
|---|---|
| sonicwall | sma6210 |
| sonicwall | sma6210 firmware |
| sonicwall | sma7210 |
| sonicwall | sma7210 firmware |
| sonicwall | sma8200v |
References
→ the Explorer · watch your stack · NVD