cbcvebase.
CVE-2026-83549
published 2026-09-01

CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000…

PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-05
Exploited in the wild
EPSS
13.84%
96.3th percentile
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Affected

8 ranges
VendorProductVersion rangeFixed in
sonicwallsma1000
sonicwallsma1000
sonicwallsma6210_firmware< 12.4.3-0352612.4.3-03526
sonicwallsma6210_firmware>= 12.5.0 < 12.5.0-0295212.5.0-02952
sonicwallsma7210_firmware< 12.4.3-0352612.4.3-03526
sonicwallsma7210_firmware>= 12.5.0 < 12.5.0-0295212.5.0-02952
sonicwallsma8200v< 12.4.3-0352612.4.3-03526
sonicwallsma8200v>= 12.5.0 < 12.5.0-0295212.5.0-02952

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.