SonicWall disclosed four vulnerabilities in Secure Mobile Access (SMA) 1000 series appliances that could allow SQL injection-based privilege escalation, unauthenticated user credential enumeration, and multi-factor authentication bypass. The issues affect SMA 1000 deployments through flaws in SQL handling and Unicode processing, with the most severe bug tracked as CVE-2026-4112 and rated CVSS 7.2. SonicWall said the vulnerabilities do not impact SSL-VPN functionality on standard SonicWall firewalls.
According to SonicWall's advisory SNWLID-2026-0003, the Unicode-related flaws can bypass TOTP protections in AMC, Workplace, or Connect Tunnel authentication flows, increasing the risk of unauthorized access. SonicWall said it has no evidence of active exploitation and provided hotfixes and fixed releases for affected SMA 1000 versions, adding that no workarounds or alternative mitigations are available, making patching the required response for exposed systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside the advisory, SonicWall instructed administrators to install hotfixes and upgrade affected SMA1000 versions to remediated releases because no workarounds or mitigations were available. The highest-rated issue identified in reporting was CVE-2026-4112 with a CVSS v3 score of 7.2.
SonicWall disclosed four vulnerabilities affecting Secure Mobile Access (SMA) 1000 series appliances, including SQL injection-based privilege escalation, unauthenticated credential enumeration, and Unicode handling flaws that can enable MFA/TOTP bypass. The advisory said there was no evidence of active exploitation and clarified that standard SonicWall firewall SSL-VPN features are not affected.
A critical vulnerability affecting SonicWall SMA1000 Appliance Management Console and Central Management Console was disclosed for version 12.4.3-02804 and earlier. The flaw could be exploited remotely without authentication to execute arbitrary commands, and SonicWall indicated exploitation may already have been observed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcepsirt.global.sonicwall.com
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.