CVE-2026-83549
SonicWall SMA 1000 appliances under attack via zero-day flaws
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Coverage 1 source
-
2026-09-02
Help Net Security
critical
SonicWall SMA 1000 appliances under attack via zero-day flaws
Attackers exploit two zero-day flaws in SonicWall SMA 1000 appliances.
Mentioned with
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands