SonicWall Warns Attackers Are Chaining Two SMA1000 Zero-Days
SonicWall has issued an urgent advisory confirming that two previously unknown vulnerabilities in its SMA1000 series appliances are being actively exploited in the wild. The company says attackers are chaining the two flaws together, using one to bypass initial defenses and the second to achieve remote code execution on affected devices.
SMA1000 appliances are widely used by enterprises to provide secure remote access to internal networks, making them an attractive target for attackers looking to establish a foothold inside corporate environments. SonicWall has not yet released full technical details of the bugs to avoid aiding further exploitation, but is urging customers to apply mitigations and monitor for suspicious activity while a patch is finalized.
This marks the latest in a string of zero-days affecting SonicWall's remote access product lines, which have repeatedly been targeted by ransomware groups and state-linked actors in recent years.