規則(EU)2024/2847に関する独立したガイド · ステータス:発効中
このページは自動(AI)翻訳であり、人によるレビューは行われていません。 ブログ記事は英語のみで提供されています。
← All news
Fast Check23 July 2026

Fast Check: After CISA's 14 July 2026 SonicWall Warning, SMA 1000 VPN Appliances Fall Under the CRA's Class I Rules

Fast Check: After CISA's 14 July 2026 SonicWall Warning, SMA 1000 VPN Appliances Fall Under the CRA's Class I Rules

On 14 July 2026, SonicWall confirmed that two zero-day vulnerabilities in its SMA 1000 secure remote access appliances were being exploited in the wild, and the same day the US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalogue with a remediation deadline of 17 July 2026. The more severe flaw, CVE-2026-15409, is an unauthenticated server-side request forgery rated CVSS 10.0; the second, CVE-2026-15410, is a post-authentication command injection that can be chained with the first so that an unauthenticated attacker reaches administrative command execution. Attackers had been using the pair since at least 22 June 2026. KEV is a United States mechanism, but the device at the centre of it, an enterprise VPN appliance, is squarely in scope of the EU Cyber Resilience Act. So this Fast Check asks a simple question: if an SMA 1000 is sold into the EU, where does it sit under the CRA, and what would an actively exploited flaw trigger?

Where a VPN appliance sits in the CRA

The CRA sorts products with digital elements into three tiers: default (self-assessed), 重要 (Annex III), and 重大 (Annex IV). Annex III splits into Class I and Class II. VPN products are named in the first band: Annex III, Class I, lists products with digital elements with the function of virtual private network (VPN). The SMA 1000 is a secure remote access gateway whose core job is to terminate encrypted remote-access sessions, so it lands in Class I, not in the default self-assessed tier. You can check any product against the tiers with our classification tool or run the full Fast Check yourself.

Class I lets you self-assess, but only on a condition

Class I sits one step below the higher-risk Class II band that covers firewalls and intrusion detection systems, but the classification still changes the conformity route. For a default product, the lightest internal control procedure (module A) in Annex VIII is enough: the manufacturer assesses its own product and signs the EU declaration of conformity. A Class I product can use that same self-assessment, but only where the condition in Article 32(2) is met: the manufacturer must have fully applied harmonised standards, common specifications or a European cybersecurity certification scheme (at assurance level at least substantial) covering the Annex I essential requirements. Where those do not exist, or are applied only in part, the product must instead go through EU-type examination (module B) plus conformity to type (module C) or full quality assurance (module H), both of which bring in a 通知機関. Our CE marking and conformity guide maps each route to its module.

The 24-hour clock an exploited flaw would start

Classification decides how a product reaches the market. Article 14 decides what happens when it is attacked. From 2026年9月11日, a manufacturer that becomes aware of an actively exploited vulnerability must send an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure being available. A KEV listing describes exactly that situation: a flaw already used in attacks, often before every customer has patched. The duty covers products already on the market, not just new launches, so an appliance shipped today would still be caught. Our Article 14 reporting guide sets out the 24, 72 and 14-day sequence.

Status at publication, 23 July 2026

Two things a Class I maker would rely on are not yet in place. ENISA's Single Reporting Platform, the single entry point manufacturers must use for Article 14 notifications, is not yet operational; ENISA has scheduled it to be live by 2026年9月11日, with a testing period beforehand. And no CRA harmonised standard has yet been cited in the Official Journal. For a Class I product that matters twice over: without a cited standard there is no Article 27 presumption of conformity, and the self-assessment route in Article 32(2) is unavailable, so a VPN maker preparing now would be planning for a notified body rather than a self-declaration.

What this means for VPN makers and buyers

The takeaway is not that SonicWall is uniquely exposed; the same logic applies to any VPN or secure remote access vendor selling into the EU. For makers, the practical steps are to confirm the Class I classification early, assume a 通知機関 route until a harmonised standard exists to build against, and stand up an internal detection and triage process that can meet a 24, 72 and 14-day rhythm once reporting begins. For buyers, a live KEV entry is a useful proxy for the vulnerability-handling maturity the CRA will eventually require of every in-scope product: a fast patch, a clear advisory, and a support period that outlasts the threat. The exploited-flaw warning is a US signal today. Under the CRA, from 11 September 2026, a comparable flaw in an EU-market VPN appliance starts a clock the manufacturer cannot pause.

Published 23 July 2026 · Fast Check. Part of the CRA insights blog on cyberresilienceact.eu.