Full-Time
Posted on 9/8/2026
Delivers firewall hardware and security services
No salary listed
Cleveland, OH, USA
Hybrid
Up to 30% travel is required.
Bachelor's, Master's, PhD
See people who can refer or advise you
SonicWall provides security products and services to protect networks, endpoints, and data for SMBs, enterprises, and government clients. Its offerings include firewalls, secure remote access, email security, and advanced threat protection that combine hardware and software with subscription updates to block ransomware, malware, and phishing. It differentiates itself with an integrated, broad security portfolio and ongoing updates plus professional services for a wide range of customers. Its goal is to help organizations maintain continuous protection against evolving cyber threats and improve security posture.
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$48M
Headquarters
Milpitas, California
Founded
1991
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Remote Work Options
Hybrid Work Options
Critical SonicWall remote code execution vulnerabilities actively exploited in attacks. Spread the love SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances. The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands. The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident Response Team investigated a case indicating active exploitation. SonicWall urged organizations to install the available platform hotfixes immediately and review exposed systems for signs of compromise. The vulnerabilities affect SMA1000 6210, 7210, and 8200v appliances running version 12.4.3-03453 or earlier, as well as version 12.5.0-02835 or earlier. SonicWall stated that SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected. SonicWall RCE vulnerabilities exploited. The most severe issue is tracked as CVE-2026-83548 and carries a CVSS score of 10.0. It is a pre-authentication server-side request forgery vulnerability in the SMA1000 Appliance Workplace interface. According to SonicWall, the flaw stems from an unintended alternate access path that can serve as a forward proxy. A remote, unauthenticated attacker could exploit this path to access sensitive internal functionality and perform unauthorized operations. The vulnerability is associated with CWE-918, covering server-side request forgery, and CWE-441, which describes an unintended proxy or confused-deputy condition. SSRF vulnerabilities are especially dangerous in remote-access appliances because they can allow attackers to make requests from the device itself, potentially bypassing network restrictions designed to protect internal services. SonicWall also addressed CVE-2026-83549, a post-authentication remote code execution flaw in the SMA1000 Appliance Management Console. The vulnerability has a CVSS score of 7.8 and stems from improper neutralization of special characters in operating system commands. An authenticated attacker with administrator privileges could exploit the command injection issue to execute arbitrary commands on the appliance operating system. While this vulnerability requires valid administrator access, it could be especially damaging when chained with another weakness that provides unauthorized access to appliance functions. Remote-access infrastructure remains a high-value target because it often sits at the edge of enterprise networks and handles user authentication, VPN connectivity, and access to internal resources. A compromised SMA appliance may provide attackers with a foothold for credential theft, lateral movement, and further network intrusion. There is no workaround for either issue. Organizations should upgrade SMA1000 appliances to version 12.4.3-03526 or later, or to version 12.5.0-02952 or later, depending on the software branch they have deployed. SonicWall also recommends contacting technical support to review appliances for indicators of compromise. If compromise indicators are found, organizations should re-image affected physical appliances or redeploy affected virtual appliances. Administrators should then change all user and administrator passwords and reset TOTP tokens to invalidate potentially stolen authentication factors. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC The post critical SonicWall remote code execution vulnerabilities actively exploited in attacks appeared first on Cyber Security News. July 15, 2026 SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA1000 Series appliances. The company is warning that attackers are actively exploiting these flaws in real-world attacks. The most critical issue, tracked as CVE-2026-15409, carries a maximum CVSS severity score of 10.0 and can be... July 15, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" Security researchers have discovered a critical privilege escalation vulnerability in SonicWall's SMA1000 appliance that attackers are actively exploiting to gain unauthorized administrative access. The vulnerability, tracked as CVE-2025-40602, affects the appliance management console and poses a significant risk to enterprise networks relying on SonicWall's remote access solutions. SonicWall PSIRT disclosed... December 18, 2025 In "Cybersecurity News - Original News Source is cybersecuritynews.com" The Australian Cyber Security Centre (ACSC) has issued a critical alert regarding a severe access control vulnerability in SonicWall products that is being actively exploited in attacks. The flaw, tracked as CVE-2024-40766, affects multiple generations of SonicWall firewalls and carries a critical CVSS score of 9.3, highlighting the significant risk... September 11, 2025 In "Cybersecurity News - Original News Source is cybersecuritynews.com"
SonicWall warns of actively exploited SMA1000 zero-day flaws. * September 2, 2026 * 02:39 AM * 0 SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness. This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices. "SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company warned in a Tuesday advisory. The two security flaws affect SMA1000 6210, 7210, and 8200v models, but they don't affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain. SonicWall urged all customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version. While the company also advised admins to re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected, it has yet to share details about these ongoing attacks or a list of IOCs it has found while investigating them. Such vulnerabilities are often targeted in attacks, given that the SMA1000 is a secure remote access appliance used by large enterprises, government, and critical infrastructure organizations. In July, two other SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410) were exploited in zero-day attacks for weeks to install custom malware on vulnerable VPN appliances. Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs have begun abusing the two vulnerabilities in the wild. The company also warned customers in December to patch another SMA1000 zero-day vulnerability (CVE-2025-40602) that hackers were chaining to gain root privileges. One month earlier, SonicWall linked state-backed hackers to a September security breach that exposed customers' firewall configuration backup files after researchers warned of more than 100 SonicWall SSLVPN accounts compromised using stolen credentials. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
SonicWall patches its second SMA zero-day pair. Anil Kale covers data protection, vulnerabilities and the business of security for... Media Partner SonicWall has patched a chained pair of SMA 1000 zero-day vulnerabilities under active exploitation, the second such pair the vendor has fixed in this product line in under two months. For security leaders who run edge remote-access gateways, the recurrence matters more than the individual bug: the same appliance shipped the same class of flaw twice, and attackers found the second pair before defenders had fully absorbed the first. The vulnerability chain. SonicWall's Product Security Incident Response Team disclosed two vulnerabilities in its SMA 1000 series Secure Mobile Access appliances, used by mid-size and large enterprises, government agencies and managed security providers to broker remote employee access to internal networks. CVE-2026-83548 is a pre-authentication server-side request forgery flaw in the appliance's Work Place interface, rated a maximum CVSS score of 10.0. It lets a remote, unauthenticated attacker force the appliance into acting as an unintended forward proxy, reaching internal functionality it was never meant to expose. CVE-2026-83549 is a lower-severity, post-authentication operating system command injection flaw in the Appliance Management Console, rated 7.8, that lets an authenticated administrator-level session execute arbitrary commands. Media Partner Why the pairing matters. Neither bug alone is unusual for an internet-facing appliance. Chained together, they are a different problem: the unauthenticated SSRF flaw can be used to reach the management console that the command-injection flaw then turns into code execution, giving an attacker with no credentials at all a path to remote code execution on the device. SonicWall said it had investigated a case indicating active exploitation of the vulnerabilities, which is the vendor's standard language for confirming attacks are already underway rather than merely theoretical. The Work Place interface is the SMA1000's user-facing web portal, the same component remote employees use to authenticate and launch their session, which is why an unauthenticated flaw there is treated as maximum severity rather than a lesser access-control gap. The affected hardware is limited to the SMA1000 6210, 7210 and 8200v models. SonicWall said the flaws do not affect SSL-VPN running on its firewalls or the separate SMA 100 series product line, a distinction worth checking carefully given how similarly the two SMA product families are named and how differently they need to be patched. Fixes are available in hotfix releases 12.4.3-03526, 12.5.0-02952 and later, and SonicWall's advisory frames the update as urgent rather than routine given the confirmed exploitation. A pattern, not an isolated incident. This is not SonicWall's first SMA1000 zero-day pair this year. In July, the vendor disclosed and patched CVE-2026-15409 and CVE-2026-15410, a pre-authentication SSRF flaw in the same Appliance Work Place interface, also rated CVSS 10.0, chained with a post-authentication command-injection flaw in the same Appliance Management Console, both also confirmed under active exploitation before a patch existed. The bug class, the interface, the console and the severity profile are effectively identical across both incidents, seven weeks apart. That repetition is the story for a security desk covering the vendor ecosystem, not just the product. Remote-access gateways sit at the network edge by design, authenticate users before anything else does, and are exposed to the internet as a matter of function rather than misconfiguration. When the same appliance ships the same shape of bug twice in two months, it says less about one bad patch and more about how much attacker attention edge access infrastructure is now getting, and how thin the margin is between disclosure and exploitation on that class of device, a gap CyberTech has tracked closely as a maximum CVSS score alone has stopped telling defenders what to patch first. Get the week's best tech coverage. Free. Read by thousands of HR, tech, and business leaders. What this means for the security leader. Patch management processes built around annual or quarterly appliance update cycles are not matched to this threat model. SMA1000 owners need hotfix 12.4.3-03526 or 12.5.0-02952 (or later) applied now, not queued behind a change-control window, given SonicWall's own confirmation of active exploitation. Because the appliance's job is authenticating remote access, a compromise here does not stay contained to the device: it hands an attacker a foothold inside the perimeter that VPN and zero-trust access gateways exist to protect. Security teams that patched the July SMA1000 pair should not treat that as evidence the product line is now hardened, in the same way unauthenticated-access flaws in ServiceNow earlier this year showed that one round of patching rarely closes an entire bug class. The two incidents share an interface and a console, which is a reasonable prompt to ask SonicWall, directly or through account teams, what structural changes are being made to the Appliance Work Place and Appliance Management Console codebases rather than patching each SSRF and command-injection pair as it surfaces. Enterprises with SMA1000 deployments should also confirm exposure by checking which of the three affected models, 6210, 7210 or 8200v, they run, since SonicWall was specific that the separate SMA 100 line and firewall SSL-VPN are unaffected. What to do now. Apply hotfix 12.4.3-03526, 12.5.0-02952 or later immediately on any SMA1000 6210, 7210 or 8200v appliance. Review Appliance Management Console access logs for administrative sessions and configuration changes that do not match known change requests, since the command-injection half of the chain requires an authenticated session that may itself be the product of a prior compromise. Treat any SMA1000 appliance that has not yet received the hotfix as a live exposure rather than a pending maintenance item, consistent with SonicWall's confirmation that exploitation is already occurring in the wild. Inventory every internet-facing SMA1000 device the organization operates, including units managed on behalf of clients by managed security service providers, since the appliance's role brokering third-party remote access means a single unpatched box can expose more than one organization's network at once. Anil Kale. Anil Kale covers data protection, vulnerabilities and the business of security for CyberTech Edition. Media Partner
SonicWall SMA 1000 zero-days enable unauthenticated RCE. The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices. September 2, 2026 Attackers are exploiting two zero-day vulnerabilities affecting select SonicWall SMA 1000 perimeter devices, and customers are urged to patch immediately. SonicWall disclosed two flaws on Tuesday: pre-authentication server-side request forgery (SSRF) vulnerability CVE-2026-83548 and post-authentication remote code execution (RCE) vulnerability CVE-2026-83549. The former is present in the SMA 1000 Appliance Work Place interface (the user facing portal) and the latter in the SMA 1000 Appliance Management Console (AMC), which is the administrator portal for SMA 1000 remote access gateways. CVE-2026-83548, the SSRF bug, was designated the maximum CVSS 3.0 score of 10. SonicWall said in its advisory that the vulnerability is caused by an unintended alternate access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the advisory read. CVE-2026-83549 carries a score of 7.8. SonicWall referred to it as a "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability"; specific conditions could enable an authenticated remote attacker to execute arbitrary OS commands leading to RCE. In a blog post about the flaws, Rapid7 wrote the vulnerabilities "can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances." Moreover, "No public proof-of-concept exploit, indicators of compromise (IOCs), or attribution for the current activity were identified in the research available at the time of publication." SonicWall noted that the vendor's Product Security Incident Response Team (PSIRT) "investigated a case indicating the active exploitation of the vulnerabilities described in this advisory." The bugs were internally discovered by SonicWall's William Perry and Adam Babis. The current exploitation activity follows attacks on two other SMA 1000 zero-days earlier this summer - CVE-2026-15409 and CVE-2026-15410 - which could similarly be chained together for RCE. SMA 1000 models 6210, 7210, and 8200v are affected, specifically versions 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. The vendor urged customers to upgrade to 12.4.3-03526/12.5.0-02952 (platform-hotfix) and higher. SMA 1000 attacks are ongoing, patch now. A spokesperson for SonicWall tells Dark Reading that these attacks are ongoing. "We have confirmed that these vulnerabilities are being actively exploited in the wild," SonicWall says. "Upon discovery, SonicWall promptly investigated and released fixed firmware. We are directing all customers running affected appliances to install the released firmware (12.4.3-03526 or 12.5.0-02952) immediately, review for indicators of compromise, and contact SonicWall technical support if any are found." If IOCs are detected, the customer should re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset TOTP tokens. Remote access gateways such as the SMA 1000 sit at the edge of enterprise networks and are frequently exposed directly to the internet, making them attractive targets for attackers. SonicWall's SMA 1000 appliances specifically have been hit with several zero-day attacks in recent years. Rapid7 noted that the role of these systems as network edge devices makes successful exploitation particularly concerning. SonicWall's guidance that compromised customers re-image hardware appliances or re-deploy virtual appliances suggests the company views successful exploitation as potentially resulting in significant control over affected systems. Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? More Insights Industry Reports
SonicWall has a new sales leader for Brazil. Angélica Paz has been with the company since 2024 and has more than 15 years of experience. August 31, 2026 - 13:58 Font size: -A+A Angélica Paz (Photo: Disclosure) SonicWall, an American information security company, has announced Angélica Paz as its new sales leader for Brazil. With more than 15 years of experience, the executive joined the company in 2024 as a territory account manager. Previously, she worked for four and a half years at ScanSource in the roles of product analyst and business development manager. From 2009 to 2019, she devoted herself to Microgenios Tecnologia e Educação, holding the positions of commercial assistant, purchasing analyst, and administrative manager. With a bachelor's degree in business administration with an emphasis on international business, trade, and commerce from Universidade Presbiteriana Mackenzie, Paz holds an MBA in digital business management and AI from the University of São Paulo (USP). In the new role, the professional aims to promote the continued growth of the entire SonicWall Brazil ecosystem, from distributors to managed security service providers, including resellers and solution integrators. "In 2026, we will continue to go to the front lines side by side with our partners, integrating technological innovations and professional skills to help CISOs anticipate and block new threats," comments Paz. Founded in 1991 in California, SonicWall is a North American multinational cybersecurity and data protection company with a strong presence in the global and Brazilian markets. The company is recognized for the development of next-generation firewalls, network security solutions, virtual private networks, endpoint protection, and cloud security. Focused on serving from small and medium-sized businesses to large corporations and government agencies, SonicWall operates mainly through a network of partners and distribution channels. Reporter at Baguete Diário