Sma1000 is a technology platform tracked across 5 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity July 25, 2026.
SMA1000 is SonicWall's Secure Mobile Access (SMA) 1000 remote-access VPN appliance used to provide secure remote connectivity for users. It is significant in cybersecurity due to exposure of remote access gateways to attackers, with recent reports highlighting a zero-day vulnerability and a critical patch to mitigate exploitation. The developments indicate active threat exposure and urgent vendor remediation for organizations relying on SMA1000 for remote access.
SonicWall has released a patch for the actively exploited zero-day vulnerability CVE-2025-40602, which affects the Appliance Management Console (AMC) of their devices. This vulnerability allows for deserialization of…
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and…
A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a…
SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability…