Exploit

Active exploitation of vulnerabilities in SonicWall SMA 1000 devices

September 2, 2026

Cybersecurity

Exploit

Key Facts

Signal Type

Exploit

Industry

Cybersecurity

Companies

SonicWall

Date

September 2, 2026

What Happened

SonicWall has addressed two vulnerabilities in its SMA 1000 series that were actively exploited. The first vulnerability allows unauthorized actions without login credentials, while the second enables attackers with admin access to execute commands on the device.

Who Is Affected

Organizations using SonicWall SMA 1000 devices for secure remote access are at risk. The NCSC assesses both the likelihood of exploitation and potential damage as high.

Market Impact

  • Increased demand for cybersecurity remediation services.
  • Potential for security vendors to offer updates and system checks.
  • Opportunity for vendors to assist in password resets and token reconfigurations.

What to Watch

Monitor for further exploitation attempts and ensure all SMA 1000 devices are updated. Organizations should also check for signs of misuse and consider reinstalling or redeploying affected devices.

Related coverage

Get cybersecurity signals in your CRM

Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.

Book a 15 min call
Dominykas Rukas - Revenanas