SonicWall reports two major security holes under active exploit
CSO Online 02.09.2026 23:22
SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authentication, highly troubling.
In its security alert, SonicWall described the first hole, tracked as CVE-2026-83548 and rated 10 (critical) in severity, as a “Pre-authentication SSRF vulnerability [that] exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.”
Exploited JFrog Artifactory bug puts software supply chain on alert
CSO Online 02.09.2026 12:24
A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.
The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August 28 and can, under default configuration, allow an unauthenticated attacker with network access to obtain administrative privileges.
Remotezugriff Sonicwall SMA1000: Angreifer verbiegen interne Dienste
Heise Security 02.09.2026 12:24
Angreifer nutzen derzeit zwei Sicherheitslücken in Sonicwall SMA1000 aus. Mittlerweile haben die Entwickler die Lücken geschlossen.
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
The Hacker News 02.09.2026 10:53
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below –
CVE-2026-83548 (CVSS score: 10.0) – A pre-authentication SSRF vulnerability in the Appliance
Jetzt patchen! Angreifer attackieren Langflow-Instanzen mit Schadcode
Heise Security 02.09.2026 07:21
Angreifer nutzen derzeit eine kritische Sicherheitslücke im KI-Tool Langflow aus. Ein Sicherheitspatch ist schon länger verfügbar.
Datenklau aus der Cloud: Tausende Dropbox-Konten über Lenovo-Bug kompromittiert
Golem 02.09.2026 06:27
Angreifer hatten Zugriff auf Dropbox-Inhalte von etwa 5.000 Nutzern. Ursache war eine Sicherheitslücke in einer alten Lenovo-Integration. (Dropbox, Lenovo)