Web_Logo
Remote Support
Security Alert: SonicWall SMA1000 Zero-Days Under Attack
Home » Security Alerts  »  Security Alert: SonicWall SMA1000 Zero-Days Under Attack

Security Alert: SonicWall SMA1000 Zero-Days Under Attack

SonicWall has confirmed two vulnerabilities in its SMA1000 remote access appliances are being actively exploited, and both have been added to the US government's list of known exploited vulnerabilities. If your business uses a SonicWall SMA1000 for staff remote access or VPN, this needs attention now.

  • What it is: Two flaws in the SMA1000 series – a critical fault (CVE-2026-15409) in the Work Place login interface that lets an attacker in without any credentials, and a second flaw (CVE-2026-15410) that lets an already-logged-in attacker run commands on the device.
  • Who is affected: Organisations running SMA1000 model appliances (firmware 6210, 7210 or 8200v) used for secure remote access to the office network.
  • What the risk is: Attackers are using these flaws right now to get into networks without needing a username or password, then potentially take further control of the device.
  • What action is needed: Apply SonicWall's hotfix (versions 12.4.3-03453 or 12.5.0-02835) immediately, and check remote access logs for anything unusual.

If you are unsure whether your business runs a SonicWall SMA1000 or need help applying the update, we recommend getting in touch with your IT provider straight away rather than waiting for the next scheduled maintenance window.

Source: CISA Known Exploited Vulnerabilities Catalog