CVE-2026-83549
published 2026-09-01CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000…
PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-05
Exploited in the wild
EPSS
13.84%
96.3th percentile
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sonicwall | sma1000 | — | — |
| sonicwall | sma1000 | — | — |
| sonicwall | sma6210_firmware | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall | sma6210_firmware | >= 12.5.0 < 12.5.0-02952 | 12.5.0-02952 |
| sonicwall | sma7210_firmware | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall | sma7210_firmware | >= 12.5.0 < 12.5.0-02952 | 12.5.0-02952 |
| sonicwall | sma8200v | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall | sma8200v | >= 12.5.0 < 12.5.0-02952 | 12.5.0-02952 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
cisa·2026-09-02·CVSS 7.8
CVE-2026-83549 [HIGH] CWE-78 SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Vulnerability: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Affected: SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adher
GHSA
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which
ghsa_unreviewed·2026-09-02
CVE-2026-83549 [HIGH] CWE-78 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
VulDB
SonicWall SMA1000 os command injection (EUVD-2026-69707)
vuldb·2026-09-01·CVSS 7.8
CVE-2026-83549 [HIGH] SonicWall SMA1000 os command injection (EUVD-2026-69707)
A vulnerability classified as very critical has been found in SonicWall SMA1000. Affected is an unknown function. Performing a manipulation results in os command injection.
This vulnerability is known as CVE-2026-83549. Remote exploitation of the attack is possible. No exploit is available.
VulnCheck
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2026·CVSS 7.8
CVE-2026-83549 [HIGH] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://previdian.com/CVE-2026-83549; https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
No detection rules found.
Metasploit
SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
metasploit·CVSS 10.0
CVE-2026-83548 [CRITICAL] SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
This module chains three issues in SonicWall SMA1000 appliances. An unauthenticated, absolute-form OPTIONS request makes the WorkPlace listener act as an unintended forward proxy (CVE-2026-83548). The module uses this access and a vendor-installed CouchDB update handler to obtain read and write access to loopback CouchDB (SMA1000-9427), then enables CouchDB's native Erlang query server and executes one command as the couchdb service account. That command derives the appliance-local ctrl-service credential and invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap script (CVE-2026-83549) executes the selected command as root. The module attempts to restore the original CouchDB logger configuration, remove its inj
Nuclei
SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
nuclei·CVSS 10.0
CVE-2026-83548 [CRITICAL] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
Template:
id: CVE-2026-83548
info:
name: SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB
author: rapid7,DhiyaneshDk
severity: critical
description: |
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
impact: |
A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
remediation: |
Apply SonicWall platform hotfix 12.4.3-03526 (12.4.x) or 12.5.0-02952 (12.5.x) immediately.
referenc
Checkpoint
7th September – Threat Intelligence Report
blogs_checkpoint·2026-09-07
CVE-2026-83548 7th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information.
Hit, a major Slovenian gambling and tour
Hackernews
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
blogs_hackernews·2026-09-03·CVSS 6.5
CVE-2026-83548 [MEDIUM] CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog after they landed in attackers' crosshairs.
The vulnerabilities are as follows -
CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVE-2026-83549 (CVSS score: 7.8) - A post-authen
Hackernews
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
blogs_hackernews·2026-09-02·CVSS 10.0
CVE-2026-83548 [CRITICAL] Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
The vulnerabilities , discovered internally by SonicWall's William Perry and Adam Babis, are listed below -
CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Rapid7
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
blogs_rapid7·2026-09-02·CVSS 10.0
CVE-2026-83548 [CRITICAL] Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
## Overview
On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances.
CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path.
CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its
2026-09-01
Published
2026-09-02
Added to CISA KEV
Exploited in the wild