
SonicWall Confirms Active Exploitation of Two Zero-Day Vulnerabilities in SMA1000 Series
Generalcybersecurityvulnerabilities
SonicWall confirmed active exploitation of two zero-day vulnerabilities in its SMA1000 series, including one critical unauthenticated flaw and another involving post-authentication code injection. The company released hotfixes to address the issues, with U.S. federal agencies required to apply the patches by 17 July 2026 or discontinue use of affected devices. No specific CVE identifiers were mentioned in the report. The vulnerabilities were targeted in real-world attacks prior to the fixes. The affected product line is the SMA1000, a secure remote access appliance.