logo

Another bad week for SonicWall as SMA 1000 zero-day under active exploit

ID: 2f966faf-71d1-513d-9375-a90eee776d4e

STIX ID: report--2f966faf-71d1-513d-9375-a90eee776d4e

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-26

Author: Carly Page

...
...

SonicWall has warned of an actively exploited zero-day (CVE-2025-40602) in SMA 1000 appliance management consoles that allows authenticated attackers to escalate privileges; it has been chained with CVE-2025-23006 to achieve unauthenticated root remote code execution. Customers are urged to apply hotfixes immediately and restrict Appliance Management Console access, as hundreds of SMA 1000 units are visible on the internet; the advisory also recalls a prior MySonicWall backup breach that exposed configuration files and was attributed to state-sponsored actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.