SonicWall SMA1000 appliances contain an OS command injection vulnerability tracked as CVE-2026-83549. The flaw allows a remote authenticated attacker with administrator privileges to execute arbitrary OS commands, leading to remote code execution. The vulnerability has been flagged by CISA and is subject to BOD 26-04, which prioritizes security updates based on risk. CISA has also issued forensic triage requirements as part of its implementation guidance. SonicWall's PSIRT has published an advisory under SNWLID-2026-0016. The vulnerability is also documented in the NVD. Organizations using SonicWall SMA1000 appliances are urged to apply patches immediately. The criticality level is rated High.