Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3759 articles · 207508 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-83549KEVEXPLOITEDPATCHED
sonicwall · sma1000

CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi

Description

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Affected Products

VendorProductVersions
sonicwallsma100012.4.3-03453 (platform-hotfix) and older versions, 12.5.0-02835 (platform-hotfix) and older versions

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016(vendor-advisory)

Related News (3 articles)

Tier D
BleepingComputer2h ago
SonicWall warns of actively exploited SMA1000 zero-day flaws
→ No new info (linked only)
Tier D
SecurityWeek3h ago
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
→ No new info (linked only)
Tier C
VulDB10h ago
CVE-2026-83549 | SonicWall SMA1000 os command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
CWECWE-78
PublishedSep 1, 2026
Trending Score116🔥
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-83548EXPKEV
CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
Trending: 119
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 108
HIGHCVE-2026-66152
CVE-2026-66152: A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to
Trending: 17
HIGHCVE-2026-66153
CVE-2026-66153: The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows
Trending: 17
CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 1, 2026
Added to CISA KEV
Sep 1, 2026
Discovered by ZDM
Sep 1, 2026
Actively Exploited
Sep 2, 2026
Patch Available
Sep 2, 2026