Skip to content
COOEY

EXPOSURES › CVE-2026-83549

CVE-2026-83549

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-09-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-83549 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

SonicWall SMA1000 appliances suffered an OS command injection flaw enabling remote authenticated attackers to execute arbitrary commands, resulting in remote code execution.

A remote authenticated attacker could exploit this OS command injection vulnerability to execute arbitrary OS commands, leading to full remote code execution on the appliance. This is a critical failure for DIB organizations relying on SonicWall for network security, as it directly compromises the integrity and confidentiality of protected systems. Organizations must immediately apply the available hotfixes and verify that their SMA1000 appliances are patched to prevent exploitation.

Shame score — A critical RCE vulnerability in a core network security appliance was actively exploited in the wild, indicating severe negligence in patch management and security engineering.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.