$ techbeacon▋
CVE & Exploits

SonicWall Alerts Users to Active Exploitation of Two New SMA1000 Zero‑Day Flaws

SonicWall Alerts Users to Active Exploitation of Two New SMA1000 Zero‑Day Flaws

SonicWall has issued an urgent advisory warning that two newly discovered zero‑day vulnerabilities in its SMA1000 series of secure remote‑access appliances are being actively exploited to execute arbitrary code on targeted networks.

The SMA1000 devices, which provide SSL VPN and remote‑management capabilities for small‑ to medium‑size enterprises, contain flaws in the web‑based management interface that can be chained together, allowing an attacker to bypass authentication and run malicious code with system‑level privileges.

According to the company’s notice, the exploits have already been observed in active campaigns against corporate environments, with attackers employing the same technique across multiple incidents. While technical specifics of the vulnerability chain remain undisclosed, SonicWall confirmed that both weaknesses can be triggered remotely without prior credentials.

The vulnerabilities were first reported by security outlet BleepingComputer, which referenced unnamed researchers that uncovered the bugs. In response, SonicWall released an emergency firmware update on Tuesday that addresses the flaws and adds further hardening measures, urging all SMA1000 users to apply the patch without delay.

Security analysts stress that zero‑day attacks on network‑edge appliances are especially worrisome because these devices often serve as gateways to internal resources. The rapid weaponization of the SMA1000 flaws highlights the critical need for prompt patch management, network segmentation, and additional controls such as multi‑factor authentication.

SonicWall said it will keep monitoring the threat landscape and assist customers in identifying any compromised systems. The company also cautioned that threat actors may attempt to leverage the same vulnerability chain against other models in its portfolio, prompting a broader security review across its product line.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related