Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
Security firm Volexity discovered in early July 2026 that threat actors had exploited a zero-day vulnerability in SonicWall Secure Mobile Access VPN appliances, compromising the devices during an active incident response investigation. The attack targeted the remote access hardware that organizations rely on to connect employees securely to corporate networks.
Why this matters: VPN appliances are supposed to be the lock on the door. When attackers find a zero-day in one, they do not just get in — they get in through the thing designed to keep them out. SonicWall SMA devices are widely used by businesses and government agencies. If your organization uses one, this is not an abstract threat. Patch cycles for network hardware are slow, and these devices are often trusted more than they should be. The incident also came to light through a breach investigation, which means real organizations were already hit before a fix existed.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.