Fast Check: After CISA's 14 July 2026 SonicWall Warning, SMA 1000 VPN Appliances Fall Under the CRA's Class I Rules
On 14 July 2026, SonicWall confirmed that two zero-day vulnerabilities in its SMA 1000 secure remote access appliances were being exploited in the wild, and the same day the US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalogue with a remediation deadline of 17 July 2026. The more severe flaw, CVE-2026-15409, is an unauthenticated server-side request forgery rated CVSS 10.0; the second, CVE-2026-15410, is a post-authentication command injection that can be chained with the first so that an unauthenticated attacker reaches administrative command execution. Attackers had been using the pair since at least 22 June 2026. KEV is a United States mechanism, but the device at the centre of it, an enterprise VPN appliance, is squarely in scope of the EU Πράξη για την Κυβερνοανθεκτικότητα. So this Fast Check asks a simple question: if an SMA 1000 is sold into the EU, where does it sit under the CRA, and what would an actively exploited flaw trigger?
Where a VPN appliance sits in the CRA
The CRA sorts products with digital elements into three tiers: default (self-assessed), σημαντικό (Annex III), and κρίσιμο (Annex IV). Annex III splits into Class I and Class II. VPN products are named in the first band: Annex III, Class I, lists products with digital elements with the function of virtual private network (VPN). The SMA 1000 is a secure remote access gateway whose core job is to terminate encrypted remote-access sessions, so it lands in Class I, not in the default self-assessed tier. You can check any product against the tiers with our classification tool or run the full Γρήγορος Έλεγχος yourself.
Class I lets you self-assess, but only on a condition
Class I sits one step below the higher-risk Class II band that covers firewalls and intrusion detection systems, but the classification still changes the conformity route. For a default product, the lightest internal control procedure (module A) in Annex VIII is enough: the manufacturer assesses its own product and signs the EU declaration of conformity. A Class I product can use that same self-assessment, but only where the condition in Article 32(2) is met: the manufacturer must have fully applied harmonised standards, common specifications or a European cybersecurity certification scheme (at assurance level at least substantial) covering the Annex I essential requirements. Where those do not exist, or are applied only in part, the product must instead go through EU-type examination (module B) plus conformity to type (module C) or full quality assurance (module H), both of which bring in a κοινοποιημένος οργανισμός. Our CE marking and conformity guide maps each route to its module.
The 24-hour clock an exploited flaw would start
Classification decides how a product reaches the market. Article 14 decides what happens when it is attacked. From 11 Σεπτεμβρίου 2026, a manufacturer that becomes aware of an actively exploited vulnerability must send an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure being available. A KEV listing describes exactly that situation: a flaw already used in attacks, often before every customer has patched. The duty covers products already on the market, not just new launches, so an appliance shipped today would still be caught. Our Article 14 reporting guide sets out the 24, 72 and 14-day sequence.
Two things a Class I maker would rely on are not yet in place. ENISA's Single Reporting Platform, the single entry point manufacturers must use for Article 14 notifications, is not yet operational; ENISA has scheduled it to be live by 11 Σεπτεμβρίου 2026, with a testing period beforehand. And no CRA harmonised standard has yet been cited in the Official Journal. For a Class I product that matters twice over: without a cited standard there is no Article 27 presumption of conformity, and the self-assessment route in Article 32(2) is unavailable, so a VPN maker preparing now would be planning for a notified body rather than a self-declaration.
What this means for VPN makers and buyers
The takeaway is not that SonicWall is uniquely exposed; the same logic applies to any VPN or secure remote access vendor selling into the EU. For makers, the practical steps are to confirm the Class I classification early, assume a κοινοποιημένος οργανισμός route until a harmonised standard exists to build against, and stand up an internal detection and triage process that can meet a 24, 72 and 14-day rhythm once reporting begins. For buyers, a live KEV entry is a useful proxy for the vulnerability-handling maturity the CRA will eventually require of every in-scope product: a fast patch, a clear advisory, and a support period that outlasts the threat. The exploited-flaw warning is a US signal today. Under the CRA, from 11 September 2026, a comparable flaw in an EU-market VPN appliance starts a clock the manufacturer cannot pause.
