CuraSec

Act active

SonicWall SMA1000 zero-days chained in active RCE attacks

2026-09-02 15:05 UTC · BleepingComputer · read the source ↗ #sonicwall#zero-day#rce
  • Engineer — Act: Actively exploited RCE zero-days on an edge appliance demand immediate response: apply SonicWall’s emergency mitigations or patches as soon as available, and treat any internet-exposed SMA1000 as potentially compromised pending confirmation.
  • SOC/IR — Act: Active exploitation of an edge SSL VPN device means compromise may predate any patch; sweep SMA1000 appliances for anomalous outbound connections and lateral movement indicators from the appliance’s IP, and initiate assume-breach review of adjacent segments.
  • Leader — Act: If SonicWall SMA1000 is in the estate, confirm remediation is underway this week and request a vendor statement on exposure scope; actively exploited RCE on a remote-access gateway is the kind of incident that surfaces in board and customer conversations.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.