Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [cve, zero-day, command-injection, actively-exploited, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: true

CVE-2026-83549

Summary

CVE-2026-83549 is a SonicWall SMA1000 zero-day command-injection flaw in the Appliance Management Console. It can be exploited by an admin user to execute arbitrary OS commands and is being chained with CVE-2026-83548 in actively exploited remote code execution attacks.

Details

SonicWall warned that threat actors actively chain two SMA1000 zero-day vulnerabilities in RCE attacks: CVE-2026-83548 (a maximum-severity SSRF-derived command-injection flaw in the SMA1000 Appliance WorkPlace interface) and CVE-2026-83549 (a command-injection flaw in the Appliance Management Console exploited by an admin user to execute arbitrary OS commands). The flaws affect SMA1000 6210, 7210 and 8200v models, but not SSL-VPN on firewalls or the SMA 100 series. Shadowserver tracks over 400 internet-exposed appliances.

Remediation

SonicWall urged customers to upgrade to the SMA1000 hotfix, re-image appliances and reset credentials/TOTP if indicators of compromise are found. Previous SMA1000 zero-days (CVE-2026-15409/15410) are already being abused by ransomware gangs, so disclosure-to-exploitation is fast for this product line.

Source