CVE-2026-83549
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
An authenticated administrator of the SMA1000 Appliance Management Console can inject malicious operating system commands through the application, allowing them to execute arbitrary code on the server. This is dangerous because it gives attackers complete control over the affected system.
Post-authentication OS command injection vulnerability in SMA1000 AMC allows an authenticated administrator to execute arbitrary OS commands via improper neutralization of special elements in command inputs. Attack vector requires valid admin credentials and specific conditions; successful exploitation results in remote code execution with system-level privileges.