Cyber News / Article / Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
Thevulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below -
SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining together both the bugs to execute arbitrary code on susceptible devices.
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that customers perform the actions outlined below -
SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The development comes more than a month after itshippedfixes to address two other flaws in the same product – CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2) – that were exploited by a threat actor dubbed UTA0533 to deploy KNUCKLEBALL malware.
Related articles
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
4 days ago
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
4 days ago
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
4 days ago
You might Also like

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack

