Security News > 2021 > April > Three Zero-Day Flaws in SonicWall Email Security Product Exploited in Attacks

SonicWall's Email Security product is affected by three vulnerabilities that have been exploited in attacks.
FireEye, whose incident response unit Mandiant spotted the vulnerabilities and their active exploitation in March, warned on Tuesday that a threat actor had been observed exploiting the SonicWall Email Security flaws to install backdoors, access emails and files, and move laterally in the victim's network.
SonicWall says the vulnerabilities impact Email Security for Windows, as well as hardware and ESXi virtual appliances.
SonicWall released security advisories for two of the exploited vulnerabilities on April 9 and 10, but only released a public security notice to warn about exploitation attempts on April 20, when it also released an advisory for the third flaw.
In a blog post describing the vulnerabilities and the attacks, FireEye said the attackers targeted the latest version of the Email Security application running on Windows Server 2012.
Through the course of this process, SonicWall was made aware of and verified certain zero-day vulnerabilities - in at least one known case, being exploited in the wild - to its hosted and on-premises email security products.
News URL
Related news
- SonicWall SMA appliances exploited in zero-day attacks (CVE-2025-23006) (source)
- SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks (source)
- Fortinet Warns of New Zero-Day Used in Attacks on Firewalls with Exposed Interfaces (source)
- 3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security Update (source)
- Patch Tuesday: January 2025 Security Update Patches Exploited Elevation of Privilege Attacks (source)
- Balancing usability and security in the fight against identity-based attacks (source)
- SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix (source)
- 5,000+ SonicWall firewalls still open to attack (CVE-2024-53704) (source)
- Security pros more confident about fending off ransomware, despite being battered by attacks (source)
- Google fixes Android kernel zero-day exploited in attacks (source)