


Perceptive Security
SOC/SIEM Consultancy

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitr…
Published:
2 September 2026 at 02:00:00
Alert date:
2 September 2026 at 20:06:16
Source:
cisa.gov

Network Infrastructure, Zero-Day Vulnerabilities, Critical Infrastructure
SonicWall SMA1000 appliances contain an OS command injection vulnerability tracked as CVE-2026-83549. The flaw allows a remote authenticated attacker with administrator privileges to execute arbitrary OS commands, leading to remote code execution. The vulnerability has been flagged by CISA and is subject to BOD 26-04, which prioritizes security updates based on risk. CISA has also issued forensic triage requirements as part of its implementation guidance. SonicWall's PSIRT has published an advisory under SNWLID-2026-0016. The vulnerability is also documented in the NVD. Organizations using SonicWall SMA1000 appliances are urged to apply patches immediately. The criticality level is rated High.
Technical details
Mitigation steps:
Affected products:
SonicWall SMA1000
Related links:
https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
https://nvd.nist.gov/vuln/detail/CVE-2026-83549
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.