logo

CVE-2025-40602: SonicWall Secure Mobile Access (SMA) 1000 Zero-Day Exploited

ID: 9996d3e4-879d-505e-9573-3a78df1cadfc

STIX ID: report--9996d3e4-879d-505e-9573-3a78df1cadfc

Feed Name: Tenable Blog

Threat Score
80/100

Date Published: 2025-12-17

Date Updated: 2026-05-01

Author: Scott Caveza

...
...

A zero-day local privilege escalation (CVE-2025-40602) in SonicWall Secure Mobile Access (SMA) 1000 was disclosed and reported as being exploited in the wild in a chained attack with CVE-2025-23006; together these flaws can enable unauthenticated attackers to achieve root code execution. SonicWall has published an advisory and fixed versions; administrators are advised to apply the provided patches or restrict AMC access as a workaround and review Tenable plugins for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.