CRITICALVulnerability
Verified
Global
Critical SonicWall SMA Gateway Auth Bypass Under Active Exploitation
Thursday, March 5, 2026 at 11:00 AM UTC·Source: SonicWall PSIRT / Arctic Wolf
Updated: Friday, March 6, 2026 at 09:00 AM UTC
Executive Summary
Authentication bypass in SonicWall SMA 1000 series gateways allows unauthenticated admin access. Active exploitation confirmed by CISA.
Analysis
CVE-2026-5135 is a critical authentication bypass in SonicWall SMA 1000 series. Unauthenticated attackers can gain admin access to the management interface and pivot into internal networks. CISA added to KEV catalog after confirming active exploitation. Arctic Wolf observed ransomware deployment following SMA compromise.
Timeline
Discovered
Feb 25, 2026
Exploitation Detected
Mar 1, 2026
Published
Mar 5, 2026
Patch Available
Mar 5, 2026