{"id":30015,"date":"2026-07-20T15:01:28","date_gmt":"2026-07-20T13:01:28","guid":{"rendered":"https:\/\/perseus.de\/active-zero-day-attacks-on-sonicwall-sma1000-act-now\/"},"modified":"2026-08-10T10:24:54","modified_gmt":"2026-08-10T08:24:54","slug":"active-zero-day-attacks-on-sonicwall-sma1000-act-now","status":"publish","type":"post","link":"https:\/\/perseus.de\/en\/active-zero-day-attacks-on-sonicwall-sma1000-act-now\/","title":{"rendered":"Active Zero-Day Attacks on SonicWall SMA1000: Act Now"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30015\" class=\"elementor elementor-30015 elementor-28855\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dcf4ec4 e-flex e-con-boxed e-con e-parent\" data-id=\"dcf4ec4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1db58c elementor-widget elementor-widget-image\" data-id=\"e1db58c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"200\" src=\"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png\" class=\"attachment-large size-large wp-image-30037\" alt=\"In the event of a current attack pattern or a security vulnerability, Perseus sends out warning emails containing specific countermeasures.\" srcset=\"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png 1024w, https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-300x75.png 300w, https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-768x192.png 768w, https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN.png 1200w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1258a43 e-flex e-con-boxed e-con e-parent\" data-id=\"1258a43\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2de4e88 e-con-full e-flex e-con e-child\" data-id=\"2de4e88\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4982c80 elementor-widget elementor-widget-text-editor\" data-id=\"4982c80\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h6>20.07.2026<\/h6>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8348bc5 elementor-widget elementor-widget-heading\" data-id=\"8348bc5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Active Zero-Day Attacks on SonicWall SMA1000: Act Now\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-eb03842 e-con-full e-flex e-con e-child\" data-id=\"eb03842\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-91d0988 elementor-widget elementor-widget-text-editor\" data-id=\"91d0988\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p> <\/p>\n<p><span style=\"font-weight: 400\">Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems &#8211; but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.  <\/span><\/p>\n<p><span style=\"font-weight: 400\">Currently, the manufacturer SonicWall warns of two security vulnerabilities in the SMA1000 series that are already being actively exploited. Since there are currently no alternative protection measures, affected companies should install the security updates provided as soon as possible and check their systems for signs of compromise as a precautionary measure. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-ceb0f40 e-flex e-con-boxed e-con e-parent\" data-id=\"ceb0f40\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffbdc12 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"ffbdc12\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-02dd0e9 e-flex e-con-boxed e-con e-parent\" data-id=\"02dd0e9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-16d621d e-con-full e-flex e-con e-child\" data-id=\"16d621d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89904c7 elementor-widget elementor-widget-text-editor\" data-id=\"89904c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What happened?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fae461d e-con-full e-flex e-con e-child\" data-id=\"fae461d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0f04793 elementor-widget elementor-widget-text-editor\" data-id=\"0f04793\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400\">The SonicWall SMA1000 Series is a system for secure remote access to corporate networks. Employees or external service providers use them to access internal systems in encrypted form. This is precisely why these devices are an attractive target for attackers.  <\/span><\/p>\n<p><span style=\"font-weight: 400\">SonicWall has published two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) that were actively exploited even before the security updates were released, so-called zero-day vulnerabilities. The U.S. cybersecurity agency CISA has therefore included both in its catalog of actively exploited vulnerabilities. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54c68ef e-flex e-con-boxed e-con e-parent\" data-id=\"54c68ef\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-96849ac elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"96849ac\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-174b215 e-flex e-con-boxed e-con e-parent\" data-id=\"174b215\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e560a6b e-con-full e-flex e-con e-child\" data-id=\"e560a6b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-013b67e elementor-widget elementor-widget-text-editor\" data-id=\"013b67e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>How does the attack work?  <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a72ed48 e-con-full e-flex e-con e-child\" data-id=\"a72ed48\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-db8754f elementor-widget elementor-widget-text-editor\" data-id=\"db8754f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400\">The attacks combine two different vulnerabilities. First, an attacker can trick the system into executing internal requests on its behalf (Server-Side Request Forgery, SSRF). This allows security mechanisms to be bypassed and other internal components to be accessed.  <\/span><\/p>\n<p><span style=\"font-weight: 400\">A second vulnerability in the management console (command injection) is then exploited to execute arbitrary system commands. Although this second vulnerability requires administrator privileges on its own, both vulnerabilities can be used together to completely compromise the system. SonicWall therefore rates this attack chain overall with the maximum severity level CVSS 10.0.  <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54465d1 e-flex e-con-boxed e-con e-parent\" data-id=\"54465d1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d02be9e elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d02be9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d3f9227 e-flex e-con-boxed e-con e-parent\" data-id=\"d3f9227\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-6059711 e-con-full e-flex e-con e-child\" data-id=\"6059711\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-26eea72 elementor-widget elementor-widget-text-editor\" data-id=\"26eea72\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What is affected? <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-724b6c6 e-con-full e-flex e-con e-child\" data-id=\"724b6c6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f0c2fb4 elementor-widget elementor-widget-text-editor\" data-id=\"f0c2fb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400\">Only the following models of the <\/span><b>SonicWall SMA1000 series<\/b> are affected<span style=\"font-weight: 400\">:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">SMA6210<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">SMA7210<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">SMA8200v<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">with firmware versions <\/span><b>12.4.3-03245 to 12.5.0-02800<\/b><span style=\"font-weight: 400\">.<\/span><\/p>\n<p><b>However, the following are not affected:  <\/b><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">SonicWall Firewalls<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">SSL VPN on SonicWall Firewalls<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">SonicWall SMA-100 Series<\/span><\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9e25b00 e-flex e-con-boxed e-con e-parent\" data-id=\"9e25b00\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-67b2d4e elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"67b2d4e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c28550e e-flex e-con-boxed e-con e-parent\" data-id=\"c28550e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-b5ac00b e-con-full e-flex e-con e-child\" data-id=\"b5ac00b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4467aca elementor-widget elementor-widget-text-editor\" data-id=\"4467aca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>How can I protect myself? <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-990ca5f e-con-full e-flex e-con e-child\" data-id=\"990ca5f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56e453f elementor-widget elementor-widget-text-editor\" data-id=\"56e453f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400\">We recommend the following measures for affected companies:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><b>First, check to see if your environment uses a SonicWall SMA1000.<\/b><span style=\"font-weight: 400\">  If not, there is no need for action in connection with this warning.<\/span><\/li>\n<\/ul>\n<p> <\/p>\n<ul>\n<li style=\"font-weight: 400\"><b>Immediately install the hotfixes provided by SonicWall<\/b><span style=\"font-weight: 400\"> (version <\/span><b>12.4.3-03453<\/b><span style=\"font-weight: 400\">, <\/span><b>12.5.0-02835<\/b><span style=\"font-weight: 400\"> or later). Since there are no workarounds available, the security update is the most important protective measure.<\/span><\/li>\n<\/ul>\n<p> <\/p>\n<ul>\n<li style=\"font-weight: 400\"><b>Check if the system has already been compromised.<\/b><span style=\"font-weight: 400\"> Signs can include unknown administrator accounts, unexpected changes to the system configuration, suspicious login attempts, attempted execution of malicious scripts, or unusual activity in the log files. SonicWall has published specific Indicators of Compromise (IOCs; https:\/\/www.sonicwall.com\/support\/notices\/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities\/kA1VN000001nv6D0AQ) that can be used to check affected systems.<\/span><\/li>\n<\/ul>\n<p> <\/p>\n<ul>\n<li style=\"font-weight: 400\">In particular, <b>check the logs for<\/b><span style=\"font-weight: 400\"> suspicious access to the endpoints <\/span><b>\/__api__\/login<\/b><span style=\"font-weight: 400\"> and <\/span><b>\/__api__\/logout<\/b><span style=\"font-weight: 400\">, unusual requests to <\/span><b>\/wsproxy<\/b>, <span style=\"font-weight: 400\"> and unexpected changes to the system configuration. These activities may indicate successful exploitation of the vulnerabilities.<\/span><\/li>\n<\/ul>\n<p> <\/p>\n<ul>\n<li style=\"font-weight: 400\"><b>If evidence of compromise is detected<\/b><span style=\"font-weight: 400\">, SonicWall recommends that the affected system be completely redeployed. You should then change all user and administrator passwords and reset any TOTP tokens you have set up for multi-factor authentication.<\/span><\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a2790c7 e-flex e-con-boxed e-con e-parent\" data-id=\"a2790c7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d4feb2c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d4feb2c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7faf510 e-flex e-con-boxed e-con e-parent\" data-id=\"7faf510\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-9a087a2 e-con-full e-flex e-con e-child\" data-id=\"9a087a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4a4eba5 elementor-widget elementor-widget-text-editor\" data-id=\"4a4eba5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Conclusion  <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f63aea7 e-con-full e-flex e-con e-child\" data-id=\"f63aea7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e249ee4 elementor-widget elementor-widget-text-editor\" data-id=\"e249ee4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400\">The current attacks show once again that remote access systems continue to be among the most important targets for cybercriminals. Although only the SonicWall SMA1000 series is affected, companies with such appliances should take the warning seriously. Since the vulnerabilities are already being actively exploited and no workarounds exist, a quick installation of the deployed hotfixes is crucial.  <\/span><\/p>\n<p><span style=\"font-weight: 400\">Even companies that are not affected can learn important lessons from this incident: Remote access systems should be updated regularly, administration access should be secured in the best possible way and security-critical systems should be continuously monitored. In this way, the risk of successful attacks can be significantly reduced in the long term. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-8530d6c e-flex e-con-boxed e-con e-parent\" data-id=\"8530d6c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3bbb54c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"3bbb54c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f2d97c9 elementor-widget elementor-widget-text-editor\" data-id=\"f2d97c9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><i>Do you want to stay informed about current threats and security vulnerabilities?<\/i><\/p>\n<p><i>Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.<\/i><\/p>\n<p> <\/p>\n<p><b>Sources &amp; Further Information<\/b><\/p>\n<p><em><span style=\"font-weight: 400\">SonicWall PSIRT Advisory SNWLID-2026-0008<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400\">CISA \u2013 Known Exploited Vulnerabilities (KEV)<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400\">BleepingComputer \u2013 <\/span><span style=\"font-weight: 400\">SonicWall warns of SMA1000 flaws exploited in zero-day attacks<\/span><\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9f86355 e-flex e-con-boxed e-con e-parent\" data-id=\"9f86355\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dd90633 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"dd90633\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems &#8211; but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.  <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[22],"tags":[],"class_list":["post-30015","post","type-post","status-publish","format-standard","hentry","category-gefahrenwarnung"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Active Zero-Day Attacks on SonicWall SMA1000: Act Now - Perseus Technologies<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Active Zero-Day Attacks on SonicWall SMA1000: Act Now - Perseus Technologies\" \/>\n<meta property=\"og:description\" content=\"Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems - but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/\" \/>\n<meta property=\"og:site_name\" content=\"Perseus Technologies\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T13:01:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-10T08:24:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Anastasia Pamoukis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anastasia Pamoukis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/\"},\"author\":{\"name\":\"Anastasia Pamoukis\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/person\\\/6c87a2feea6439d0ead16c8f0f07e40b\"},\"headline\":\"Active Zero-Day Attacks on SonicWall SMA1000: Act Now\",\"datePublished\":\"2026-07-20T13:01:28+00:00\",\"dateModified\":\"2026-08-10T08:24:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/\"},\"wordCount\":713,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\",\"articleSection\":[\"Gefahrenwarnung\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/\",\"url\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/\",\"name\":\"Active Zero-Day Attacks on SonicWall SMA1000: Act Now - Perseus Technologies\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\",\"datePublished\":\"2026-07-20T13:01:28+00:00\",\"dateModified\":\"2026-08-10T08:24:54+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#primaryimage\",\"url\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\",\"contentUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/perseus.de\\\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/perseus.de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Active Zero-Day Attacks on SonicWall SMA1000: Act Now\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#website\",\"url\":\"https:\\\/\\\/perseus.de\\\/\",\"name\":\"perseus-web.de\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/perseus.de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#organization\",\"name\":\"perseus-web.de\",\"url\":\"https:\\\/\\\/perseus.de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/PerseusTechnologie_Color-2.png\",\"contentUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/PerseusTechnologie_Color-2.png\",\"width\":536,\"height\":172,\"caption\":\"perseus-web.de\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/person\\\/6c87a2feea6439d0ead16c8f0f07e40b\",\"name\":\"Anastasia Pamoukis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"caption\":\"Anastasia Pamoukis\"},\"sameAs\":[\"https:\\\/\\\/perseus.de\"],\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/author\\\/anastasia-pamoukis\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Active Zero-Day Attacks on SonicWall SMA1000: Act Now - Perseus Technologies","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/","og_locale":"en_US","og_type":"article","og_title":"Active Zero-Day Attacks on SonicWall SMA1000: Act Now - Perseus Technologies","og_description":"Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems - but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.","og_url":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/","og_site_name":"Perseus Technologies","article_published_time":"2026-07-20T13:01:28+00:00","article_modified_time":"2026-08-10T08:24:54+00:00","og_image":[{"width":1200,"height":300,"url":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN.png","type":"image\/png"}],"author":"Anastasia Pamoukis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Anastasia Pamoukis","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#article","isPartOf":{"@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/"},"author":{"name":"Anastasia Pamoukis","@id":"https:\/\/perseus.de\/#\/schema\/person\/6c87a2feea6439d0ead16c8f0f07e40b"},"headline":"Active Zero-Day Attacks on SonicWall SMA1000: Act Now","datePublished":"2026-07-20T13:01:28+00:00","dateModified":"2026-08-10T08:24:54+00:00","mainEntityOfPage":{"@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/"},"wordCount":713,"commentCount":0,"publisher":{"@id":"https:\/\/perseus.de\/#organization"},"image":{"@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#primaryimage"},"thumbnailUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","articleSection":["Gefahrenwarnung"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/","url":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/","name":"Active Zero-Day Attacks on SonicWall SMA1000: Act Now - Perseus Technologies","isPartOf":{"@id":"https:\/\/perseus.de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#primaryimage"},"image":{"@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#primaryimage"},"thumbnailUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","datePublished":"2026-07-20T13:01:28+00:00","dateModified":"2026-08-10T08:24:54+00:00","breadcrumb":{"@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#primaryimage","url":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","contentUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png"},{"@type":"BreadcrumbList","@id":"https:\/\/perseus.de\/aktive-zero-day-angriffe-auf-sonicwall-sma1000-jetzt-handeln\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/perseus.de\/"},{"@type":"ListItem","position":2,"name":"Active Zero-Day Attacks on SonicWall SMA1000: Act Now"}]},{"@type":"WebSite","@id":"https:\/\/perseus.de\/#website","url":"https:\/\/perseus.de\/","name":"perseus-web.de","description":"","publisher":{"@id":"https:\/\/perseus.de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/perseus.de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/perseus.de\/#organization","name":"perseus-web.de","url":"https:\/\/perseus.de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/perseus.de\/#\/schema\/logo\/image\/","url":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/03\/PerseusTechnologie_Color-2.png","contentUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/03\/PerseusTechnologie_Color-2.png","width":536,"height":172,"caption":"perseus-web.de"},"image":{"@id":"https:\/\/perseus.de\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/perseus.de\/#\/schema\/person\/6c87a2feea6439d0ead16c8f0f07e40b","name":"Anastasia Pamoukis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","caption":"Anastasia Pamoukis"},"sameAs":["https:\/\/perseus.de"],"url":"https:\/\/perseus.de\/en\/author\/anastasia-pamoukis\/"}]}},"_links":{"self":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30015","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/comments?post=30015"}],"version-history":[{"count":7,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30015\/revisions"}],"predecessor-version":[{"id":30069,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30015\/revisions\/30069"}],"wp:attachment":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/media?parent=30015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/categories?post=30015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/tags?post=30015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}