“Audit your entire customer base for SonicWall SMA1000 systems today — this is mandatory compliance now — and flag any running unpatched Fortinet or Defender instances for emergency patching this week.”
ShieldBreak (CVE-2026-69414): Unpatched Defender Bypass with Public PoC Code Available
A new elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine — dubbed ShieldBreak — bypasses the earlier RoguePlanet fix patched in July. Microsoft has assigned CVE-2026-69414, confirmed public disclosure, and acknowledged that proof-of-concept exploit code exists, but no official fix is available yet. Workaround: prevent untrusted code execution on endpoints; apply application whitelisting and monitor for anomalous Defender engine activity.
Read more →CISA Adds Two SonicWall SMA1000 Vulnerabilities to KEV — FCEB Deadline Was September 5
CISA added two SonicWall SMA1000 appliance vulnerabilities to the KEV catalog on 2 September 2026, including CVE-2026-83549 (OS command injection, CWE-78), confirming active real-world exploitation. Federal agencies had until 5 September to remediate; MSPs with SMA1000 deployments should treat this as a same-week emergency given the edge-network position of these devices. Workaround: Apply SonicWall-provided mitigations immediately; if patches are unavailable, CISA advises considering discontinuing use of the affected product.
Read more →Fortinet Leads 2026 Unauthenticated Vulnerability Count — Eight CVEs Across Portfolio, Several Actively Exploited
A mid-2026 analysis found Fortinet had the highest count of unauthenticated vulnerabilities of any major firewall vendor in 2026, with eight disclosed across its portfolio and several under active exploitation including SSL-VPN patch bypass cases. Palo Alto Networks had the most dangerous exploited firewall-OS flaws, including a confirmed GlobalProtect authentication bypass (CVE-2026-0257) with public PoC. Workaround: Track FortiGuard PSIRT and CISA KEV closely; treat 'unauthenticated + internet-facing' advisories as same-week patches regardless of vendor.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.