CISA added CVE-2026-83549, a post-authentication OS command injection flaw in the SonicWall SMA1000 Appliance Management Console, to its Known Exploited Vulnerabilities catalog on 2026-09-02 with a three-day remediation deadline.
What Is It
CVE-2026-83549 is an improper neutralization of special elements used in an OS command (CWE-78) in the SMA1000 Appliance Management Console (AMC). Under specific conditions, an authenticated attacker can execute arbitrary OS commands on the appliance, resulting in code execution in the context of the management console.
SonicWall PSIRT assigned a CVSS 3.1 base score of 7.8 (HIGH), vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. That vector describes a local attack vector requiring low privileges, not a remote, administrator-only condition, with no user interaction, unchanged scope, and high confidentiality, integrity, and availability impact. Defenders should note the tension between the scored vector and narrative descriptions of this flaw as remote and administrator-gated: the CVSS metrics imply a lower privilege bar and local access, so threat models built solely around "admin-only, therefore low risk" understate the exposure. Treat any authenticated access to the AMC, including access obtained through credential reuse, session hijack, or a chained pre-auth flaw, as sufficient to reach this bug until the vendor clarifies.
CISA's SSVC assessment marks exploitation as active, automatable as no, and technical impact as total. The automatable: no rating is consistent with the local attack vector, since exploitation is not readily scriptable at internet scale. The NVD record was published 2026-09-01 and is in Analyzed status.
Why It Matters
CISA's inclusion of this CVE in the KEV catalog confirms active exploitation in the wild. The KEV entry lists known ransomware campaign use as Unknown, but flags forensic triage as required: meaning affected organizations are expected to check for evidence of compromise, not merely patch.
Because the vulnerability requires prior authenticated access, its appearance in KEV suggests attackers are likely obtaining a foothold on or against these appliances by some other means and using CVE-2026-83549 to escalate to command execution. If that reading is correct, patching alone would not address how the initial access was gained; a plausible reason why forensic triage accompanies the patching requirement here, though CISA has not stated its rationale.
The due date is 2026-09-05, only three days after the 2026-09-02 addition, which is an unusually compressed remediation window.
What's Vulnerable
Per SonicWall, affected versions are:
- 12.4.3-03453 (platform-hotfix) and older
- 12.5.0-02835 (platform-hotfix) and older
NVD CPE data identifies the affected platforms as SonicWall SMA8200v, SMA6210, and SMA7210 (Linux-based), with fixed builds at 12.4.3-03526 and 12.5.0-02952.
Patch Status
CISA's required action: apply mitigations per vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." Where mitigations are unavailable, follow applicable BOD 26-04 cloud services guidance or discontinue use of the product. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Refer to SonicWall advisory SNWLID-2026-0016 for vendor fix details.
Alongside patching, restrict AMC reachability to a dedicated management network, audit all accounts with AMC access, and rotate credentials for any account that could have been used to reach the console during the exposure window.
Sources
- SonicWall PSIRT, SNWLID-2026-0016: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549
- NVD, CVE-2026-83549: https://nvd.nist.gov/vuln/detail/CVE-2026-83549
- CISA BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk