
Work Here?
SonicWall provides security products and services to protect networks, endpoints, and data for SMBs, enterprises, and government clients. Its offerings include firewalls, secure remote access, email security, and advanced threat protection that combine hardware and software with subscription updates to block ransomware, malware, and phishing. It differentiates itself with an integrated, broad security portfolio and ongoing updates plus professional services for a wide range of customers. Its goal is to help organizations maintain continuous protection against evolving cyber threats and improve security posture.
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$48M
Headquarters
Milpitas, California
Founded
1991
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$48M
Above
Industry Average
Funded Over
0 Rounds
Remote Work Options
Hybrid Work Options
SonicWall VPN Vulnerabilities: SonicWall VPN Security vs ZTNA and Secure Access Alternatives. If your SonicWall VPN is internet-facing, treat it as a high-value target and reduce its role as soon as you can. Patch it, restrict access, enforce MFA, and start moving sensitive apps toward ZTNA or another identity-first access model. Traditional VPN still has uses, but it should not be the only front door to your business. TLDR: SonicWall VPN appliances have been hit by serious vulnerabilities over the years, especially in SSL VPN and SMA products, and attackers love them because one exposed gateway can unlock broad network access. A 200-person company with 60 remote staff may think one VPN box is simple, but if that device is compromised, 30% of the workforce's access path becomes a risk multiplier. ZTNA reduces that blast radius by granting access per user, per app, and per session. For example, a contractor can reach only Jira and a test server, not the whole internal subnet. Why SonicWall VPN keeps getting attention. SonicWall firewalls and secure mobile access products are common in small and mid-sized businesses. That popularity makes them attractive to attackers. A criminal group does not need to guess what you use if your VPN portal announces itself on the open internet. The problem is not that SonicWall is uniquely weak. The problem is the VPN model. A VPN gateway sits at the edge, accepts remote logins, and often connects users to broad network zones. If that gateway has a vulnerability, weak credentials, stale firmware, or poor MFA coverage, the damage can spread fast. Known SonicWall issues have included authentication bypasses, SQL injection, buffer overflows, and flaws in SSL VPN portals or SMA appliances. Some were exploited in the wild. Some affected older firmware. Some pushed admins into rushed patch cycles over a weekend. Honestly, it feels like VPN boxes have become the smoke alarm that starts chirping at 2:00 a.m. What makes VPN vulnerabilities so risky? A VPN is often treated as a trusted bridge. Once a user connects, the internal network may assume that user belongs there. That can be dangerous. * Large access zones: Users may reach more systems than they need. * Stolen credentials: Password reuse and phishing still work far too often. * Delayed patching: Firmware updates can require downtime, testing, and change approval. * Internet exposure: Attackers can scan VPN portals all day. * Legacy clients: Old VPN clients may linger on laptops for years. Expect to waste time on small operational headaches too. A firmware update may take 20 minutes, but checking compatibility, scheduling downtime, warning users, and confirming client behavior can turn it into a three-hour job. That delay matters when a vulnerability is already being exploited. SonicWall VPN security: what good looks like. If you keep SonicWall VPN in place, tighten it hard. Do not treat it as a simple "set and forget" service. * Patch quickly: Subscribe to vendor advisories and build an emergency patch process. * Use MFA for every login: No exceptions for admins, contractors, or "temporary" accounts. * Disable unused portals and services: Reduce what attackers can hit. * Restrict source IPs where possible: Allow access only from known offices, partner ranges, or managed devices. * Segment the network: A VPN user should not land in the same zone as domain controllers. * Log aggressively: Track failed logins, odd geographies, impossible travel, and new device use. * Remove stale users: Former employees and old vendor accounts are low-effort attack paths. These steps help, but they do not change the core shape of VPN access. The user still enters through a central doorway. If that doorway breaks, you have a bad day. ZTNA vs VPN: The security difference. Zero Trust Network Access, or ZTNA, flips the model. Instead of connecting a user to a network, it connects a verified user to a specific application. Access is based on identity, device health, location, role, risk score, and policy. With a VPN, Jane from finance might connect and see file shares, internal web apps, and database segments if routing permits it. With ZTNA, Jane gets access to the payroll app only after MFA, device checks, and policy approval. If her laptop lacks disk encryption or has an outdated agent, access can be blocked or reduced. The biggest gain is smaller blast radius. A stolen password should not equal broad internal access. A vulnerable gateway should not expose half the company. ZTNA also hides private apps from public scanning because many services are not directly exposed to the internet. Where SonicWall VPN still makes sense. VPN is not dead. It still works for site-to-site links, admin access to isolated environments, and legacy systems that cannot support modern access brokers. Some teams also need full tunnel routing for specific compliance or traffic inspection needs. The key is to narrow the use case. Keep VPN for what truly requires network-level access. Move common business apps, contractor access, developer portals, and SaaS-adjacent workflows to more controlled methods. Secure access alternatives to consider. Most organizations do not replace VPN with a single tool. They build a cleaner access stack. * ZTNA platforms: Best for private app access without broad network exposure. * SASE or SSE services: Combine secure web gateway, cloud access security, data controls, and private app access. * Identity-aware proxies: Good for browser-based internal apps. * Privileged access management: Better for admin sessions, server access, and audit trails. * VDI or browser isolation: Useful for contractors, unmanaged devices, and sensitive workflows. A practical plan might look like this: keep SonicWall VPN for 10 network admins, move 120 employees to ZTNA for internal apps, and require privileged session recording for server access. That mix is often safer than trying to make one VPN appliance handle every remote access need. Migration without chaos. Start with visibility. List every user group, app, subnet, and vendor that touches the VPN. Then decide what each group actually needs. You may find that many users connect to VPN only to reach one intranet page or one file share. * Map current VPN usage: Review logs for 30 to 60 days. * Pick low-risk apps first: Move simple web apps to ZTNA before complex admin tools. * Enforce device posture: Require encryption, patches, endpoint protection, and screen lock. * Run VPN and ZTNA side by side: Avoid a big bang switch. * Reduce VPN permissions: As apps move, shrink VPN routes and access groups. * Set a retirement target: Do not let the old setup live forever. What to watch during a SonicWall incident. If a SonicWall advisory drops, move fast. Check the affected product, firmware version, exposure, and logs. Look for new admin accounts, odd login times, strange source countries, changed VPN bookmarks, and new scheduled tasks on systems reached through VPN. Also rotate credentials if compromise is possible. VPN credentials are often reused across other systems. If you use Active Directory, review privileged groups and recent authentication events. A patched appliance is good, but it does not remove an attacker who already got inside. The bottom line. SonicWall VPN can be secured, but it should not carry your whole remote access strategy. Keep it patched, locked down, monitored, and limited. Then shift routine access to ZTNA or secure access services that verify every request instead of trusting a network tunnel. The smarter goal is not "VPN or no VPN." The goal is less exposed access, fewer broad permissions, and tighter control per app. That is how you cut risk without making remote work painful.
Related stories. September 21, 2026 Right about the time that tech exec Michael Crean decided to put his company, Solutions Granted, up for sale about three years ago, he noticed an uptick in interest in the managed security service provider business. Tactacam provides cellular-connected trail and security cameras to more than one million subscribers. Addison, Ill.-based Dickson provides environmental monitoring services and serves customers in more than 50 countries. "Security started to become the cool kids club for real," Crean tells Mergers & Acquisitions. "So, there were a lot of people coming around, knocking on the door." After teaming up with adviser Eric McAlpine of Momentum Cyber, Crean sold Solutions Granted to SonicWall, the Milpitas, Calif.-based cybersecurity company backed by Francisco Partners, in a deal announced in November of 2023. Crean, who is now senior vice president of managed services for SonicWall, says interest around acquisition targets in the cybersecurity space has grown even stronger since then, due partly to the increased threat from hackers and scammers armed with tools enhanced with AI. "What we're dealing with the cyber landscape today is war," Crean says. "I think that's probably one reason that we see that the M&A space is incredibly hot. We need better technology to defend our national infrastructure." The best way to improve technology at a company is to build it, partner with it or purchase it through a merger, and buying it "seems like the quickest, most desirable way to go at the moment," he adds. "What we're dealing with in the cyber landscape today is war. I think that's probably one reason we see that the M&A space is incredibly hot." Michael Crean, SonicWall [email protected] During the early part of 2026, larger acquirers focused on add-on deals to grow their scale, and smaller players teamed up to face AI threats. "More deals at lower total value is a clear middle market signal," says Keith Skirbe, a managing director in Houlihan Lokey's technology group. AI Threats To be sure, cybersecurity dealmaking faces some headwinds. The sector faces a "risk-off environment" tied to jitters about AI impacting the software industry, Skirbe says. Trent Hickman, co-managing partner of VSS Capital Partners, says the so-called "SAAS-pocalypse" has led to more caution due to "the question mark about the impact of AI on the underlying software platforms" at cybersecurity companies. But this hasn't kept VSS and other GPs from shopping around the sector. Hickman says VSS has been spending "a lot of time" this year reviewing a cybersecurity business that is focused on implementing and managing so-called zero-trust architecture for commercial and government clients that play a role in U.S. defense. One example of the rising threat level against Uncle Sam came with Anthropic's decision to delay the full release of its new AI software products, Mythos 5 and Fable 5, due to concerns from the company and the U.S. government that they could contain powerful tools for cybercriminals. Anthropic has since released a more secure version of it. "The Department of War's cybersecurity operations and vendors have to be really on the bleeding edge of sophistication here because the threat actors are very much sophisticated and becoming more so every day, particularly with their use of AI," Hickman says. "Their ability to penetrate these defenses is as high as it's ever been." VSS typically invests in companies that generate $5 million to $15 million of Ebitda. From an add-on acquisition perspective, it's a broader range. VSS will also look at smaller deals that will give the firm access to a new geography or product line, or to particularly attractive talent that can fit well strategically and culturally with the existing platform. VSS's potential cybersecurity acquisition would fit the firm's focus on managed services platform companies such as Coretelligent and Centroid, according to Hickman. Along with motivated sellers, cybersecurity M&A continues to receive tailwinds from the growing need for threat protection. Crean says he's seeing "a lot of really good young talent" out there that are doing things that the big players such as Cisco (Nasdaq: CSCO), Check Point Software (Nasdaq: CHKP), Palo Alto Networks (Nasdaq: PANW) or CrowdStrike (Nasdaq: CRWD), haven't thought of yet. "When you start bringing in these new ideas into your business, you start to supercharge your capabilities," Crean says. Skirbe says large cybersecurity vendors will continue to be under pressure from customers drowning in vendor sprawl. "Rather than build, they're acquiring small to mid-sized companies that fill specific capability gaps," he mentions. With deal flow skewing toward smaller tuck-ins and capability acquisitions, leading players have been attracting strong investor interest and commanding premium valuations. Aikido Security, Claroty, Torq and Upwind are all crossing valuation thresholds of more than $1 billion amid continued appetite for platforms, according to Houlihan Lokey (NYSE: HL). Crean says the industry will continue to work to cut down on crime that costs billions. "I dealt with an individual recently who had retired, and unfortunately, he fell for a phishing scam, and he lost millions of dollars. We're talking about a really smart person," Crean says. "Cybersecurity and M&A are not just for the Fortune 500, they're for everyone. It's more important now than it ever has been."
Cybercriminals chain two SonicWall vulnerabilities to break into remote-access appliances. SonicWall disclosed two vulnerabilities in its SMA1000 remote-access appliances on 1 September, and cybercriminals are already exploiting both. CVE-2026-83548 scores a maximum 10.0 out of 10 (Critical) CVSS score and CVE-2026-83549 scores 7.8 (High). Chained together, they let a cybercriminal with no username or password run commands on the appliance. What are these vulnerabilities? An SMA1000 is the gateway staff log in to when they work remotely. It sits at the edge of the network and faces the internet by design. CVE-2026-83548 is a Server-Side Request Forgery (SSRF), a vulnerability that tricks a server into making network requests on an outsider's behalf. SonicWall describes an unintended alternate access path in its Work Place portal, the page employees use to sign in. That path turns the appliance into an unintended forward proxy, relaying an outsider's requests to internal systems that should be out of reach. No login is needed. CVE-2026-83549 sits in SonicWall's Appliance Management Console, the administrator control panel. It is a command injection vulnerability whereby the appliance treats part of a cybercriminal's input as an instruction to its operating system, not as plain data. On its own, it needs an administrator account, but the chain removes that obstacle. The first vulnerability carries the attacker to the management console, and the second one runs the commands. Why this is dangerous A cybercriminal that completes the chain controls the appliance. From there they can: * Read and alter traffic passing through the virtual private network (VPN). * Collect employee credentials as they arrive. * Use the device to reach deeper into the corporate network. Remote-access gateways are a well-known ransomware entry point, because they hold access to everything behind them. SonicWall confirmed cybercriminals exploited both vulnerabilities as zero-days, so attacks began before a patch existed. CISA added the pair to its KEV Catalog on 2 September and US federal agencies had until 5 September to fix them - far shorter than the usual three weeks. SonicWall has not named the group behind the attacks or released indicators of compromise. The Shadowserver Foundation counts more than 400 SMA1000 appliances reachable online. Affected software The vulnerabilities affect SMA1000 models 6210, 7210 and 8200v running platform-hotfix firmware 12.4.3-03453 or earlier, or 12.5.0-02835 or earlier. SonicWall states that SMA 100 series appliances and the SSL-VPN feature on SonicWall firewalls are not affected. Mitigation and next steps Upgrade to 12.4.3-03526 or 12.5.0-02952 or later. SonicWall offers no workaround, so patching is the only fix. Organizations that suspect a breach should re-image the appliance (or re-deploy it if virtual), then reset every user and administrator password along with all time-based one-time password (TOTP) tokens. Need help? If you have any questions, don't hesitate to reach out.
Critical SonicWall remote code execution vulnerabilities actively exploited in attacks. Spread the love SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances. The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands. The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident Response Team investigated a case indicating active exploitation. SonicWall urged organizations to install the available platform hotfixes immediately and review exposed systems for signs of compromise. The vulnerabilities affect SMA1000 6210, 7210, and 8200v appliances running version 12.4.3-03453 or earlier, as well as version 12.5.0-02835 or earlier. SonicWall stated that SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected. SonicWall RCE vulnerabilities exploited. The most severe issue is tracked as CVE-2026-83548 and carries a CVSS score of 10.0. It is a pre-authentication server-side request forgery vulnerability in the SMA1000 Appliance Workplace interface. According to SonicWall, the flaw stems from an unintended alternate access path that can serve as a forward proxy. A remote, unauthenticated attacker could exploit this path to access sensitive internal functionality and perform unauthorized operations. The vulnerability is associated with CWE-918, covering server-side request forgery, and CWE-441, which describes an unintended proxy or confused-deputy condition. SSRF vulnerabilities are especially dangerous in remote-access appliances because they can allow attackers to make requests from the device itself, potentially bypassing network restrictions designed to protect internal services. SonicWall also addressed CVE-2026-83549, a post-authentication remote code execution flaw in the SMA1000 Appliance Management Console. The vulnerability has a CVSS score of 7.8 and stems from improper neutralization of special characters in operating system commands. An authenticated attacker with administrator privileges could exploit the command injection issue to execute arbitrary commands on the appliance operating system. While this vulnerability requires valid administrator access, it could be especially damaging when chained with another weakness that provides unauthorized access to appliance functions. Remote-access infrastructure remains a high-value target because it often sits at the edge of enterprise networks and handles user authentication, VPN connectivity, and access to internal resources. A compromised SMA appliance may provide attackers with a foothold for credential theft, lateral movement, and further network intrusion. There is no workaround for either issue. Organizations should upgrade SMA1000 appliances to version 12.4.3-03526 or later, or to version 12.5.0-02952 or later, depending on the software branch they have deployed. SonicWall also recommends contacting technical support to review appliances for indicators of compromise. If compromise indicators are found, organizations should re-image affected physical appliances or redeploy affected virtual appliances. Administrators should then change all user and administrator passwords and reset TOTP tokens to invalidate potentially stolen authentication factors. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC The post critical SonicWall remote code execution vulnerabilities actively exploited in attacks appeared first on Cyber Security News. July 15, 2026 SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA1000 Series appliances. The company is warning that attackers are actively exploiting these flaws in real-world attacks. The most critical issue, tracked as CVE-2026-15409, carries a maximum CVSS severity score of 10.0 and can be... July 15, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" Security researchers have discovered a critical privilege escalation vulnerability in SonicWall's SMA1000 appliance that attackers are actively exploiting to gain unauthorized administrative access. The vulnerability, tracked as CVE-2025-40602, affects the appliance management console and poses a significant risk to enterprise networks relying on SonicWall's remote access solutions. SonicWall PSIRT disclosed... December 18, 2025 In "Cybersecurity News - Original News Source is cybersecuritynews.com" The Australian Cyber Security Centre (ACSC) has issued a critical alert regarding a severe access control vulnerability in SonicWall products that is being actively exploited in attacks. The flaw, tracked as CVE-2024-40766, affects multiple generations of SonicWall firewalls and carries a critical CVSS score of 9.3, highlighting the significant risk... September 11, 2025 In "Cybersecurity News - Original News Source is cybersecuritynews.com"
SonicWall patches its second SMA zero-day pair. Anil Kale covers data protection, vulnerabilities and the business of security for... Media Partner SonicWall has patched a chained pair of SMA 1000 zero-day vulnerabilities under active exploitation, the second such pair the vendor has fixed in this product line in under two months. For security leaders who run edge remote-access gateways, the recurrence matters more than the individual bug: the same appliance shipped the same class of flaw twice, and attackers found the second pair before defenders had fully absorbed the first. The vulnerability chain. SonicWall's Product Security Incident Response Team disclosed two vulnerabilities in its SMA 1000 series Secure Mobile Access appliances, used by mid-size and large enterprises, government agencies and managed security providers to broker remote employee access to internal networks. CVE-2026-83548 is a pre-authentication server-side request forgery flaw in the appliance's Work Place interface, rated a maximum CVSS score of 10.0. It lets a remote, unauthenticated attacker force the appliance into acting as an unintended forward proxy, reaching internal functionality it was never meant to expose. CVE-2026-83549 is a lower-severity, post-authentication operating system command injection flaw in the Appliance Management Console, rated 7.8, that lets an authenticated administrator-level session execute arbitrary commands. Media Partner Why the pairing matters. Neither bug alone is unusual for an internet-facing appliance. Chained together, they are a different problem: the unauthenticated SSRF flaw can be used to reach the management console that the command-injection flaw then turns into code execution, giving an attacker with no credentials at all a path to remote code execution on the device. SonicWall said it had investigated a case indicating active exploitation of the vulnerabilities, which is the vendor's standard language for confirming attacks are already underway rather than merely theoretical. The Work Place interface is the SMA1000's user-facing web portal, the same component remote employees use to authenticate and launch their session, which is why an unauthenticated flaw there is treated as maximum severity rather than a lesser access-control gap. The affected hardware is limited to the SMA1000 6210, 7210 and 8200v models. SonicWall said the flaws do not affect SSL-VPN running on its firewalls or the separate SMA 100 series product line, a distinction worth checking carefully given how similarly the two SMA product families are named and how differently they need to be patched. Fixes are available in hotfix releases 12.4.3-03526, 12.5.0-02952 and later, and SonicWall's advisory frames the update as urgent rather than routine given the confirmed exploitation. A pattern, not an isolated incident. This is not SonicWall's first SMA1000 zero-day pair this year. In July, the vendor disclosed and patched CVE-2026-15409 and CVE-2026-15410, a pre-authentication SSRF flaw in the same Appliance Work Place interface, also rated CVSS 10.0, chained with a post-authentication command-injection flaw in the same Appliance Management Console, both also confirmed under active exploitation before a patch existed. The bug class, the interface, the console and the severity profile are effectively identical across both incidents, seven weeks apart. That repetition is the story for a security desk covering the vendor ecosystem, not just the product. Remote-access gateways sit at the network edge by design, authenticate users before anything else does, and are exposed to the internet as a matter of function rather than misconfiguration. When the same appliance ships the same shape of bug twice in two months, it says less about one bad patch and more about how much attacker attention edge access infrastructure is now getting, and how thin the margin is between disclosure and exploitation on that class of device, a gap CyberTech has tracked closely as a maximum CVSS score alone has stopped telling defenders what to patch first. Get the week's best tech coverage. Free. Read by thousands of HR, tech, and business leaders. What this means for the security leader. Patch management processes built around annual or quarterly appliance update cycles are not matched to this threat model. SMA1000 owners need hotfix 12.4.3-03526 or 12.5.0-02952 (or later) applied now, not queued behind a change-control window, given SonicWall's own confirmation of active exploitation. Because the appliance's job is authenticating remote access, a compromise here does not stay contained to the device: it hands an attacker a foothold inside the perimeter that VPN and zero-trust access gateways exist to protect. Security teams that patched the July SMA1000 pair should not treat that as evidence the product line is now hardened, in the same way unauthenticated-access flaws in ServiceNow earlier this year showed that one round of patching rarely closes an entire bug class. The two incidents share an interface and a console, which is a reasonable prompt to ask SonicWall, directly or through account teams, what structural changes are being made to the Appliance Work Place and Appliance Management Console codebases rather than patching each SSRF and command-injection pair as it surfaces. Enterprises with SMA1000 deployments should also confirm exposure by checking which of the three affected models, 6210, 7210 or 8200v, they run, since SonicWall was specific that the separate SMA 100 line and firewall SSL-VPN are unaffected. What to do now. Apply hotfix 12.4.3-03526, 12.5.0-02952 or later immediately on any SMA1000 6210, 7210 or 8200v appliance. Review Appliance Management Console access logs for administrative sessions and configuration changes that do not match known change requests, since the command-injection half of the chain requires an authenticated session that may itself be the product of a prior compromise. Treat any SMA1000 appliance that has not yet received the hotfix as a live exposure rather than a pending maintenance item, consistent with SonicWall's confirmation that exploitation is already occurring in the wild. Inventory every internet-facing SMA1000 device the organization operates, including units managed on behalf of clients by managed security service providers, since the appliance's role brokering third-party remote access means a single unpatched box can expose more than one organization's network at once. Anil Kale. Anil Kale covers data protection, vulnerabilities and the business of security for CyberTech Edition. Media Partner
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$48M
Headquarters
Milpitas, California
Founded
1991
Find jobs on Simplify and start your career today