logo

Sonicwall warns of new SMA1000 zero-day exploited in attacks

ID: ecc9d364-f555-549b-ac16-540aa1d24999

STIX ID: report--ecc9d364-f555-549b-ac16-540aa1d24999

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-12-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SonicWall warned of an actively exploited zero-day chain against SMA1000 appliances that chains a medium-severity local privilege escalation (CVE-2025-40602) with a critical pre-auth deserialization RCE (CVE-2025-23006, CVSS 9.8) to achieve root-level remote code execution; vendors have released hotfixes and over 950 exposed devices remain visible online, raising significant risk to organizations using these remote-access gateways.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.