CVE-2026-83549
HIGH · 7.8 KEV EPSS 8.5%KEV confirmation, vendor + CERT-FR active exploitation alerts, multi-source corroboration within 24h.
What: Post-authentication OS command injection in SonicWall SMA1000 Appliance Management Console (CVSS 7.8) allowing remote code execution by authenticated administrators.
Why it matters: KEV-listed as of 2026-09-02 with active exploitation confirmed. CERT-FR and SonicWall vendor advisories report in-the-wild attacks. Rapid7 and security outlets covering active exploitation status same-day post-disclosure.
Where it's seen: International CERT alerts (CERT-FR), vendor security advisories, Bluesky discussion linking CVE-2026-83548 and 83549 as twin SMA1000 flaws. Defender and practitioner alerts emphasizing immediate patching required. No public PoC yet but exploitation campaigns reported.
RISK: CRITICAL — KEV-listed active exploitation, post-auth RCE, dual SMA1000 vulns under attack, urgent patching signaled.
Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVSS 3.1 breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Local
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High