Active Exploitation of SonicWall Remote-Access Appliances
A confirmed active-exploitation campaign against SonicWall SMA1000 appliances reportedly chains pre-auth SSRF and RCE, renewing scrutiny of perimeter remote-access infrastructure. The operational lesson is to combine emergency patching with reimaging, credential resets, forensic review and exposure validation; the market lesson is durable demand for secure access and compromise-assessment capabilities.
Sources (2)
Updated Sep 8, 2026