A compromised SMA1000 is not just a broken login box. Once attackers get in, it can hand over credentials and open a path into the internal network, so patching the appliance alone may leave the real compromise untouched.
SecurityWeek reports active zero-day use of CVE-2026-15409 and CVE-2026-15410 against SonicWall SMA1000 appliances. The flaws let unauthenticated attackers open a WebSocket tunnel to restricted services and escalate to root; vendors saw credential harvesting, and in some cases pivots into corporate networks that supported ransomware activity.
The practical risk is that the gateway itself becomes part of the intrusion path, not just the entry point. That makes SMA1000 compromise a containment problem for internal services and any accounts exposed through the device.