Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems – but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.
Currently, the manufacturer SonicWall warns of two security vulnerabilities in the SMA1000 series that are already being actively exploited. Since there are currently no alternative protection measures, affected companies should install the security updates provided as soon as possible and check their systems for signs of compromise as a precautionary measure.
What happened?
The SonicWall SMA1000 Series is a system for secure remote access to corporate networks. Employees or external service providers use them to access internal systems in encrypted form. This is precisely why these devices are an attractive target for attackers.
SonicWall has published two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) that were actively exploited even before the security updates were released, so-called zero-day vulnerabilities. The U.S. cybersecurity agency CISA has therefore included both in its catalog of actively exploited vulnerabilities.
How does the attack work?
The attacks combine two different vulnerabilities. First, an attacker can trick the system into executing internal requests on its behalf (Server-Side Request Forgery, SSRF). This allows security mechanisms to be bypassed and other internal components to be accessed.
A second vulnerability in the management console (command injection) is then exploited to execute arbitrary system commands. Although this second vulnerability requires administrator privileges on its own, both vulnerabilities can be used together to completely compromise the system. SonicWall therefore rates this attack chain overall with the maximum severity level CVSS 10.0.
What is affected?
Only the following models of the SonicWall SMA1000 series are affected:
with firmware versions 12.4.3-03245 to 12.5.0-02800.
However, the following are not affected:
How can I protect myself?
We recommend the following measures for affected companies:
Conclusion
The current attacks show once again that remote access systems continue to be among the most important targets for cybercriminals. Although only the SonicWall SMA1000 series is affected, companies with such appliances should take the warning seriously. Since the vulnerabilities are already being actively exploited and no workarounds exist, a quick installation of the deployed hotfixes is crucial.
Even companies that are not affected can learn important lessons from this incident: Remote access systems should be updated regularly, administration access should be secured in the best possible way and security-critical systems should be continuously monitored. In this way, the risk of successful attacks can be significantly reduced in the long term.
Do you want to stay informed about current threats and security vulnerabilities?
Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.
Sources & Further Information
SonicWall PSIRT Advisory SNWLID-2026-0008
CISA – Known Exploited Vulnerabilities (KEV)
BleepingComputer – SonicWall warns of SMA1000 flaws exploited in zero-day attacks