TechNewsReel
Live

SonicWall SMA 1000 Zero-Days Actively Exploited for Remote Code Execution

Attackers are chaining two vulnerabilities to bypass security controls and gain full control over secure remote access appliances.

TechNewsReel Newsroom · September 2, 2026

SonicWall has issued an urgent warning after discovering that threat actors are actively exploiting two zero-day vulnerabilities in its SMA 1000 series appliances. These flaws allow attackers to gain full control over targeted systems via remote code execution (RCE).

According to SonicWall and the Cybersecurity and Infrastructure Security Agency (CISA), attackers are chaining two specific vulnerabilities—CVE-2026-15409 and CVE-2026-15410—to bypass security controls. CISA has already added these flaws to its Known Exploited Vulnerabilities catalog, confirming that the exploits are being used in the wild. In response, SonicWall has released the necessary patches and hotfixes to close these security gaps and is urging all customers to apply them immediately.

The Role of Edge Appliances

The SMA 1000 series is designed to provide secure remote access and VPN capabilities, serving as a gateway for employees to connect to corporate resources from external locations. Because these devices are designed to be accessible from the public internet, they reside at the very edge of a company's network perimeter. This positioning makes them high-value targets for sophisticated threat actors who seek a reliable point of initial entry into a corporate environment.

Risks of Perimeter Compromise

The ability to execute remote code on a perimeter device is particularly dangerous because it allows attackers to bypass standard authentication mechanisms. Once an attacker achieves RCE on an SMA 1000 appliance, they effectively establish a foothold inside the internal network. From this position, attackers can move laterally to other servers, steal sensitive corporate data, or deploy ransomware across the organization. Because the appliance is a trusted node in the network architecture, malicious activity originating from it can often evade traditional internal security monitoring.

Next Steps for Administrators

Organizations utilizing SMA 1000 series appliances should prioritize the deployment of the latest hotfixes provided by SonicWall. Security teams are advised to review system logs for any signs of unauthorized access or unusual activity that may indicate a prior compromise. While the patches address the immediate vulnerabilities, the active nature of the exploitation suggests that administrators should remain vigilant for further indicators of compromise as more details emerge from CISA and security researchers.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.