• CISA KEV
  • EXPLOITED

CVE-2026-83549: authenticated os command injection in SonicWall SMA1000 Appliances

An authenticated administrator can execute arbitrary operating-system commands on SonicWall SMA1000 Appliances, leading to remote code execution (CVE-2026-83549). The issue affects SMA1000 Appliance Management Console builds 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older. An attacker needs valid administrator credentials and network access to the management interface to exploit this flaw.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.1076
CWE
CWE-78
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent — CISA added this CVE to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline (2026-09-05), indicating immediate action is required for federal assets and high-risk internet-facing appliances.

What is CVE-2026-83549?

An authenticated administrator can execute arbitrary operating-system commands on SonicWall SMA1000 Appliances, leading to remote code execution (CVE-2026-83549). The issue affects SMA1000 Appliance Management Console builds 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older. An attacker needs valid administrator credentials and network access to the management interface to exploit this flaw. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of SonicWall SMA1000 Appliances are affected?

BRANCHAFFECTEDFIXED
12.x12.4.3-03453 (platform-hotfix) and older versions
12.x12.5.0-02835 (platform-hotfix) and older versions

Is CVE-2026-83549 being exploited?

CISA added CVE-2026-83549 to the Known Exploited Vulnerabilities catalog on 2026-09-02, and U.S. federal agencies must address it by 2026-09-05.

How to fix CVE-2026-83549

  1. Restrict network access to SMA1000 management interfaces to trusted hosts and VPNs only.
  2. Rotate administrator credentials and enforce multi-factor authentication where supported.
  3. Follow SonicWall’s vendor guidance and apply any recommended configuration mitigations immediately.
  4. Monitor SMA1000 logs and alerting for suspicious administrator actions and unexpected command execution.

Frequently asked questions

Is CVE-2026-83549 being actively exploited?

CISA added CVE-2026-83549 to its Known Exploited Vulnerabilities catalog on 2026-09-02, and federal agencies were required to remediate by 2026-09-05.

Which SMA1000 Appliances versions are affected by CVE-2026-83549?

SonicWall SMA1000 Appliance builds 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older are listed as affected.

Is there a patch for CVE-2026-83549?

No fixed versions are listed in the available advisory data; apply vendor mitigations and access restrictions until SonicWall releases a patch.

Does CVE-2026-83549 require authentication?

Yes. The vulnerability requires authenticated access as an administrator to the SMA1000 Appliance Management Console.

References