Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall patches two SMA 1000 flaws after finding evidence they were actively exploited, possibly as a chain for remote code execution.

The Hacker News The Hacker News
漏洞分析零日漏洞云安全远程代码执行漏洞利用

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.

The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below -

SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining together both the bugs to execute arbitrary code on susceptible devices.

The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -

Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that customers perform the actions outlined below -

SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The development comes more than a month after it shipped fixes to address two other flaws in the same product – CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2) – that were exploited by a threat actor dubbed UTA0533 to deploy KNUCKLEBALL malware.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.