Cybersecurity Sep 3, 2026Add to bookmarks

The Register and The Hacker News reported on September 2, 2026, that SonicWall SMA1000 appliances are once again under active attack, with two zero-days capable of forming a full exploit chain. Immediate operational priority.
Two reports were published on September 2, 2026:
We are tracking this as part of a series of critical RCE flaws affecting enterprise platforms (SAP, ServiceNow with three CVSS 10.0 CVEs, Ivanti, MOVEit). SonicWall SMA1000 is a Secure Mobile Access (SMA) gateway deployed at the enterprise perimeter — historically the most targeted class of product by ransomware groups.
Perimeter remote access appliances have been a favored vector for ransomware groups since 2020. The pattern is familiar: a critical CVE drops, a public exploit circulates, ransomware affiliates scan the internet within hours.
Three aggravating factors are present here:
The Hacker News reports that the two active SMA1000 0-days could form an attack chain — the classic scenario that turns unauthenticated access into full appliance compromise.
Takeaway: perimeter remote access appliances remain in 2026 the preferred entry point for ransomware groups. Every SonicWall/Fortinet/Ivanti/Palo Alto advisory must be treated as a P0 alert, regardless of CVSS score. Here, two active, chainable 0-days: do not delay.
Article produced by artificial intelligence, reviewed under human editorial control.
RCE sur plateformes enterprise SaaS 2026