CRITICALVulnerability
Verified
Global

Critical SonicWall SMA Gateway Auth Bypass Under Active Exploitation

·Source: SonicWall PSIRT / Arctic Wolf

Updated:

Executive Summary

Authentication bypass in SonicWall SMA 1000 series gateways allows unauthenticated admin access. Active exploitation confirmed by CISA.

Analysis

CVE-2026-5135 is a critical authentication bypass in SonicWall SMA 1000 series. Unauthenticated attackers can gain admin access to the management interface and pivot into internal networks. CISA added to KEV catalog after confirming active exploitation. Arctic Wolf observed ransomware deployment following SMA compromise.

Timeline

Discovered
Feb 25, 2026
Exploitation Detected
Mar 1, 2026
Published
Mar 5, 2026
Patch Available
Mar 5, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-5135
Source Attribution

Originally published by SonicWall PSIRT / Arctic Wolf on Mar 5, 2026. Verified by: CISA, SonicWall, Arctic Wolf.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-105704 — A vulnerability was identified in SourceCodester Drug Recommendation System 1.0....

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.

CVE-2026-105704
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105571 — A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is ...

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early throu

CVE-2026-105571
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105486 — A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the functio...

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d9

CVE-2026-105486
NIST NVD