peter bassill · operator
$ cve CVE-2026-83549 JSON

CVE-2026-83549 KEV

7.8
HIGH · CVSS 3.1 · EPSS 10.8% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-05.

Description

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS10.76% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2026-09-05
Public exploitnone known
Published2026-09-01
Last modified2026-09-21

CISA KEV

NameSonicWall SMA1000 Appliances OS Command Injection Vulnerability
Added2026-09-02
Due2026-09-05
Vendor / productSonicWall / SMA1000 Appliances
Ransomware usenone reported

Affected (5)

VendorProduct
sonicwallsma6210
sonicwallsma6210 firmware
sonicwallsma7210
sonicwallsma7210 firmware
sonicwallsma8200v

References

→ the Explorer  ·  watch your stack  ·  NVD