In the event of a current attack pattern or a security vulnerability, Perseus sends out warning emails containing specific countermeasures.
20.07.2026

Active Zero-Day Attacks on SonicWall SMA1000: Act Now

Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems – but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.

Currently, the manufacturer SonicWall warns of two security vulnerabilities in the SMA1000 series that are already being actively exploited. Since there are currently no alternative protection measures, affected companies should install the security updates provided as soon as possible and check their systems for signs of compromise as a precautionary measure.

What happened?

The SonicWall SMA1000 Series is a system for secure remote access to corporate networks. Employees or external service providers use them to access internal systems in encrypted form. This is precisely why these devices are an attractive target for attackers.

SonicWall has published two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) that were actively exploited even before the security updates were released, so-called zero-day vulnerabilities. The U.S. cybersecurity agency CISA has therefore included both in its catalog of actively exploited vulnerabilities.

How does the attack work?

The attacks combine two different vulnerabilities. First, an attacker can trick the system into executing internal requests on its behalf (Server-Side Request Forgery, SSRF). This allows security mechanisms to be bypassed and other internal components to be accessed.

A second vulnerability in the management console (command injection) is then exploited to execute arbitrary system commands. Although this second vulnerability requires administrator privileges on its own, both vulnerabilities can be used together to completely compromise the system. SonicWall therefore rates this attack chain overall with the maximum severity level CVSS 10.0.

What is affected?

Only the following models of the SonicWall SMA1000 series are affected:

  • SMA6210
  • SMA7210
  • SMA8200v

with firmware versions 12.4.3-03245 to 12.5.0-02800.

However, the following are not affected:

  • SonicWall Firewalls
  • SSL VPN on SonicWall Firewalls
  • SonicWall SMA-100 Series

How can I protect myself?

We recommend the following measures for affected companies:

  • First, check to see if your environment uses a SonicWall SMA1000. If not, there is no need for action in connection with this warning.

  • Immediately install the hotfixes provided by SonicWall (version 12.4.3-03453, 12.5.0-02835 or later). Since there are no workarounds available, the security update is the most important protective measure.

  • Check if the system has already been compromised. Signs can include unknown administrator accounts, unexpected changes to the system configuration, suspicious login attempts, attempted execution of malicious scripts, or unusual activity in the log files. SonicWall has published specific Indicators of Compromise (IOCs; https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ) that can be used to check affected systems.

  • In particular, check the logs for suspicious access to the endpoints /__api__/login and /__api__/logout, unusual requests to /wsproxy, and unexpected changes to the system configuration. These activities may indicate successful exploitation of the vulnerabilities.

  • If evidence of compromise is detected, SonicWall recommends that the affected system be completely redeployed. You should then change all user and administrator passwords and reset any TOTP tokens you have set up for multi-factor authentication.

Conclusion

The current attacks show once again that remote access systems continue to be among the most important targets for cybercriminals. Although only the SonicWall SMA1000 series is affected, companies with such appliances should take the warning seriously. Since the vulnerabilities are already being actively exploited and no workarounds exist, a quick installation of the deployed hotfixes is crucial.

Even companies that are not affected can learn important lessons from this incident: Remote access systems should be updated regularly, administration access should be secured in the best possible way and security-critical systems should be continuously monitored. In this way, the risk of successful attacks can be significantly reduced in the long term.

Do you want to stay informed about current threats and security vulnerabilities?

Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.

Sources & Further Information

SonicWall PSIRT Advisory SNWLID-2026-0008

CISA – Known Exploited Vulnerabilities (KEV)

BleepingComputer – SonicWall warns of SMA1000 flaws exploited in zero-day attacks