SMA1000 AMC command injection exploited (CVE-2026-83549)
CVE-2026-83549
CVE-2026-83549: Active exploitation of SMA1000 AMC OS command injection grants admin RCE (CVSS 7.8). Apply vendor patch or restrict AMC access now.
Actively exploited in the wild - CVE-2026-83549 is a high-severity OS command injection in the SMA1000 Appliance Management Console (AMC) that lets an authenticated administrator execute arbitrary system commands, achieving remote code execution on the appliance. SonicWall has released a patch; update immediately to block confirmed attacks.
Overview
The SMA1000 Appliance Management Console is the centralized web-based interface used to configure and monitor SonicWall SMA1000 secure access appliances. CVE-2026-83549 is an improper neutralization flaw: after authentication, the AMC fails to sanitize certain input fields before passing them to the underlying operating system shell. A remote attacker who has already obtained administrator-level credentials for the AMC can inject their own OS commands into these fields.
Attackers are exploiting this in the wild, confirmed by CISA’s Known Exploited Vulnerabilities (KEV) catalog. The CVSS score is 7.8 (HIGH). The vector is notable: attack complexity is low, no user interaction is required, and the attacker needs only low privileges once they hold an admin account. The local attack vector means the attacker must already have a foothold on the management network or possess stolen admin credentials.
Impact
Successful exploitation gives the attacker full command execution on the underlying SMA1000 operating system with the privileges of the AMC service. From that shell, an attacker can:
- Install persistent backdoors or malware on the appliance.
- Read sensitive configuration files, including VPN credentials and certificate material.
- Modify firewall and access policies to open tunnels into the protected network.
- Disable logging or delete forensic evidence of the intrusion.
- Potentially pivot to other systems reachable from the SMA1000 management interface.
Because the AMC is a management plane, compromise of this console often signals a foothold inside the trusted administrative network, making lateral movement easier.
Remediation and Mitigation
- Update the SMA1000 firmware to the latest patched release from SonicWall. Check the vendor’s security advisory for the exact version that resolves CVE-2026-83549.
- Restrict access to the AMC to trusted administrative IPs only. Do not expose the management console to the internet or broad internal segments.
- Enforce multi-factor authentication (MFA) on all AMC administrator accounts. The vulnerability requires an admin session; MFA substantially raises the barrier for attackers who steal credentials.
- Audit AMC logs for unusual command activity or unauthorized configuration changes. Review administrator account lists for unknown or dormant users.
- If immediate patching is impossible, consider temporarily disabling remote AMC access until the update can be applied.
Additional details on this and related incidents are available in our security news section, and historical breach context can be found in our breach reports.
Security Insight
CVE-2026-83549 is part of a troubling pattern: management consoles are becoming the preferred initial target for attackers precisely because they concentrate high privilege in a single exposed surface. The fact that this requires an already-compromised administrator account, yet still makes CISA’s KEV list, suggests the attackers pairing this with credential theft or phishing are finding the AMC a reliable post-exploitation staging ground. Organizations should treat any SMA1000 admin account as a crown-jewel asset, not a routine login, and segment the management plane accordingly.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitiz...
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability tha...
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to...
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application depl...