Skip to content

SonicWall SMA1000: Zero-Day Vulnerabilities Actively Exploited

Bottom line: Attackers are actively exploiting two zero-day vulnerabilities in SonicWall SMA1000, with at least one classified as critical and identified as an SSRF flaw.

Two security vulnerabilities, including a critical SSRF vulnerability, in the SonicWall SMA1000 series are currently being actively exploited by attackers. Operators must immediately deploy patches and check their systems for compromises.

According to security researchers, two vulnerabilities in the SonicWall SMA1000 series are currently being exploited in the wild. At least one flaw is an SSRF vulnerability (Server-Side Request Forgery), classified as critical, which allows attackers to generate unauthorized requests from the vulnerable server.

The active exploitation of these flaws underscores the urgency of immediate response. As a remote access solution, the SMA1000 is often positioned at an exposed point in the network perimeter and serves as gateway to internal systems — an attack vector that threat actors systematically exploit.

Operators should deploy available patches without delay. In parallel, it is recommended to search network logs and access records for suspicious activity, particularly unauthorized remote sessions, unexpected file changes, or connections to known command-and-control servers. Focus should be on the timeframe of known exploitation to define the window of potential compromise.


Source: www.security-insider.de · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: