A critical OS command injection vulnerability in SonicWall SMA1000 Appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

A critical OS command injection vulnerability in SonicWall SMA1000 appliances, identified as CVE-2026-83549, was exploited on the same day it was publicly disclosed. The vulnerability, which carries a CVSS score of 7.8, was published on September 1, 2026, and subsequently added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026.
The flaw exists within the SMA1000 Appliance Management Console (AMC) and is described as an "Improper Neutralization of Special Elements used in an OS Command." Under specific conditions, this post-authentication vulnerability could allow a remote authenticated attacker with administrative privileges to execute arbitrary operating system commands, potentially leading to remote code execution.
Evidence of active exploitation emerged rapidly. VulnCheck KEV, a commercial research entity, listed the vulnerability as exploited on September 1, 2026, the same day as its disclosure. The EUVD (ENISA, European Union) and CISA KEV catalogs both confirmed exploitation by September 2, 2026. Multiple public reports detailing exploitation were collected starting September 1, 2026, with the latest sighting of exploitation activity recorded on September 4, 2026.
CISA has issued a directive requiring federal agencies to apply vendor-provided mitigations by September 5, 2026. This mandate falls under CISA’s BOD 26-04, which prioritizes security updates based on risk. For cloud services or situations where mitigations are unavailable, CISA advises discontinuing product use. Stakeholders are responsible for assessing their assets' internet exposure and ensuring compliance with these patching guidelines.
SonicWall has acknowledged the vulnerability with the identifier SNWLID-2026-0016 and has published details on their PSIRT portal. The rapid exploitation highlights the critical importance of applying security updates promptly, especially for vulnerabilities that are publicly disclosed and quickly added to known exploited lists.

CVE-2026-81578, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-82078, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.