
🛡️ **SonicWall SMA1000 Authentication Bypass & RCE — Active Exploitation Ongoing**
Published Wednesday, September 02, 2026 at 04:50 PM PT BLUF: SonicWall disclosed September 1 two zero-day vulnerabilities (CVE-2026-83549, CVE-2026-83548) in SMA1000 Secure Mobile Access appliances; both actively exploited in the wild. One permits remote authentication bypass; the second enables arbitrary code execution. Vendors have released patches. Organizations running SMA1000 must apply updates immediately. DETAILS Vulnerability 1 (CVE-2026-83549): Remote attack vector that bypasses authentication on SMA1000 appliances. Attackers can access protected resources without credentials. ...