GKRootWire
Dev Tools Frustrated Developer Builds a Text Editor From ScratchDev Tools WebFPGA Brings FPGA Programming to the BrowserAI New Research Finds Hidden Symbolic Patterns Inside Neural NetworksGadgets iRobot's New Flagship Roomba Seals Itself to Your CarpetSecurity SonicWall Warns Attackers Are Chaining Two SMA1000 Zero-DaysGadgets Dell's New 14S Brings MacBook-Style Colors to Budget Student LaptopsDev Tools Frustrated Developer Builds a Text Editor From ScratchDev Tools WebFPGA Brings FPGA Programming to the BrowserAI New Research Finds Hidden Symbolic Patterns Inside Neural NetworksGadgets iRobot's New Flagship Roomba Seals Itself to Your CarpetSecurity SonicWall Warns Attackers Are Chaining Two SMA1000 Zero-DaysGadgets Dell's New 14S Brings MacBook-Style Colors to Budget Student Laptops
Security

SonicWall Warns Attackers Are Chaining Two SMA1000 Zero-Days

Threat actors are combining a pair of unpatched flaws in SonicWall's SMA1000 secure access appliances to gain remote code execution.

SonicWall has issued an urgent advisory confirming that two previously unknown vulnerabilities in its SMA1000 series appliances are being actively exploited in the wild. The company says attackers are chaining the two flaws together, using one to bypass initial defenses and the second to achieve remote code execution on affected devices.

SMA1000 appliances are widely used by enterprises to provide secure remote access to internal networks, making them an attractive target for attackers looking to establish a foothold inside corporate environments. SonicWall has not yet released full technical details of the bugs to avoid aiding further exploitation, but is urging customers to apply mitigations and monitor for suspicious activity while a patch is finalized.

This marks the latest in a string of zero-days affecting SonicWall's remote access product lines, which have repeatedly been targeted by ransomware groups and state-linked actors in recent years.

Why it matters: Remote access gateways sit at the network perimeter, so a chained RCE exploit here can hand attackers a direct path into internal systems before any patch exists. Given SonicWall's history of being targeted by ransomware crews, organizations running SMA1000 gear should treat this as a priority incident, not a routine patch-later advisory.

Sources: BleepingComputer