Skip to content
Threat Feed
high threat exploited

Active Exploitation of SonicWall SMA 1000 Series Appliances

SonicWall has addressed two actively exploited vulnerabilities, CVE-2024-5091 and CVE-2024-5092, in the SMA 1000 series that allow for unauthenticated unauthorized actions and authenticated command execution.

CVE search metadata

CVE search record: CVE-2024-5091. Severity: high. CVSS: 7.4. EPSS: 0.30%. KEV: no. Product: SMA 1000 Series. Brief: Active Exploitation of SonicWall SMA 1000 Series Appliances. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma-exploitation/

CVE search record: CVE-2024-5092. Severity: medium. CVSS: 6.4. EPSS: 0.32%. KEV: no. Product: SMA 1000 Series. Brief: Active Exploitation of SonicWall SMA 1000 Series Appliances. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma-exploitation/

SonicWall has released security updates for its SMA 1000 series appliances to remediate two vulnerabilities currently being exploited by threat actors in the wild. The first vulnerability, CVE-2024-5091, permits an unauthenticated remote attacker to perform unauthorized actions on the affected appliance. The second vulnerability, CVE-2024-5092, can be leveraged by an attacker who has already obtained administrative credentials to execute arbitrary commands at the operating system level. Given the combination of active exploitation and the critical nature of these edge devices, these vulnerabilities represent a high risk to organizations. Defenders should prioritize patching and initiate forensic reviews of administrative access logs and appliance integrity to identify any prior unauthorized access or persistent backdoors established during the exploitation window.

Impact

Successful exploitation of these vulnerabilities allows for full system compromise, enabling unauthorized access to sensitive network traffic and lateral movement into the protected internal environment. Organizations relying on SMA 1000 appliances for secure remote access are at immediate risk of data exfiltration and persistent network intrusion.

Recommendation

  • Immediately apply the latest security patches provided by SonicWall to all SMA 1000 series appliances.
  • Review administrative access logs for suspicious sessions or anomalous command execution indicative of exploitation of CVE-2024-5092.
  • Conduct an immediate audit of user accounts and privilege assignments to identify potentially compromised credentials used to exploit CVE-2024-5092.
  • Monitor network traffic logs for unexpected outbound connections from the management interface of the SMA appliances.

Immediate actions

Apply firmware updates to all SMA 1000 appliances

IT Operations 24h

Threat Hunt

Anomalous administrative login sessions

T1078 high high confidence hunt now

Data: Appliance authentication logs

Mitigations

Patch SMA 1000 series to the latest firmware version

immediate IT Operations

CVE-2024-5091, CVE-2024-5092