Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
In plain language
AI Act nowCVE-2026-83549 is an issue in the SMA1000 Appliance Management Console where a logged-in administrator can be tricked into running operating-system commands, giving attackers full control; because it’s already being exploited, a typical small business should act now if you use this console.
CVE-2026-83549 is an OS Command Injection in SMA1000 Appliance Management Console that allows a logged-in high-privilege administrator to have crafted input trigger unauthorized OS command execution, resulting in full device compromise; it is listed in CISA KEV and reported as actively exploited in the wild.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- 7th September – Threat Intelligence Reporten-us·Check Point Research·
- Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecasten-us·Help Net Security· Roundup Claude ShinyHunters
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Minersen·The Hacker News· Exploited SonicWall SMA 1000 Qilin
- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEen·Dark Reading· Exploited SonicWall SMA 1000 zero-day
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chainen·The Hacker News· Exploited SonicWall SMA 1000 Series zero-day
- SonicWall SMA 1000 appliances under attack via zero-day flawsen-us·Help Net Security· Exploited SonicWall SMA 1000 Appliances zero-day
- SonicWall warns of actively exploited SMA1000 zero-day flawsen-us·BleepingComputer· Exploited SMA1000 zero-day
- SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacksen-us·SecurityWeek· Exploited SMA1000 zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-83549 and every CVE in our database. Create a free account — no credit card required.
Create Free Account