CISA (the US Cybersecurity and Infrastructure Security Agency) has issued an urgent warning that attackers are actively exploiting two critical vulnerabilities in SonicWall SMA1000 secure remote access appliances, a firewall and VPN product used by many Australian businesses for remote access.
- What it is: Two vulnerabilities affect SonicWall SMA1000 appliances. One, a server-side request forgery flaw, carries the maximum possible severity score of 10 out of 10. The second is a command injection flaw in the management console.
- Who is affected: Any organisation running a SonicWall SMA1000 appliance for secure remote access or VPN connectivity into their network.
- What the risk is: The two flaws can be chained together, giving an unauthenticated attacker a path to remote code execution and direct access to internal systems sitting behind the firewall.
- What action is needed: Apply SonicWall's vendor-recommended mitigations immediately, or take the appliance offline until patched if mitigation is not possible. US federal agencies have been given until 5 September 2026 to act, which reflects how seriously this is being treated.
If your business runs SonicWall equipment, we recommend checking your patch and mitigation status today rather than waiting for a scheduled maintenance window.