BusinessCybersecurityNewswireTechnologyWhat's Buzzing

SonicWall SMA zero-day attacks exploit CVE-2026-15409, CVE-2026-15410

Originally published on: July 15, 2026
▼ Summary

– SonicWall fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) in SMA 1000 series appliances and urges customers to upgrade firmware and check for compromise.
– CVE-2026-15409 is a critical SSRF flaw in the Work Place interface, while CVE-2026-15410 is a high-severity code injection flaw in the Management Console, exploited together in attacks.
– Patching alone is insufficient; customers must review logs for indicators of compromise and follow guidance to re-image or re-deploy appliances and reset credentials.
– Affected firmware versions include 12.4.3-03245 through 12.5.0-02800 on SMA6210, SMA7210, and SMA8200v appliances.
– CISA added the flaws to its Known Exploited Vulnerabilities catalog, ordering federal agencies to address them by July 17, 2026.

SonicWall has confirmed that two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances are being actively exploited in the wild. The company has released emergency firmware patches for CVE-2026-15409 and CVE-2026-15410, and is strongly urging customer organizations to upgrade immediately while also searching for signs of compromise.

If the specified indicators of compromise are detected on an affected system, SonicWall advises administrators to either re-image hardware appliances or re-deploy virtual appliances, change all user and administrator passwords, and reset TOTP tokens.

Understanding the vulnerabilities

The SMA 1000 series serves as a secure remote access (SSL VPN) gateway for mid-to-large enterprises, multinational corporations, government agencies, and managed security service providers.

CVE-2026-15409 is a critical server-side request forgery (SSRF) flaw residing in the SMA1000 Appliance Work Place interface. This bug could allow a remote, unauthenticated attacker to force the appliance into sending requests to unintended destinations.

The second flaw, CVE-2026-15410, is a high-severity code injection vulnerability in the SMA1000 Appliance Management Console. It permits a remote attacker who is authenticated as an administrator to execute arbitrary OS commands, effectively achieving remote code execution.

In observed attack campaigns, these two vulnerabilities are being chained together. A SonicWall spokesperson confirmed that the bugs “are being actively exploited in the wild and are not unique to SonicWall.” Upon discovery, the company investigated, developed a firmware patch, and notified impacted customers.

SonicWall sent an advance alert to customers, directing them to contact SonicWall Support to receive the hotfixes (v12.4.3-03453 and 12.5.0-02835) before their public availability on July 14, 2026. The company also developed a diagnostic script to assist with resolution and has mitigation efforts underway, with support teams handling suspicious activity on a case-by-case basis.

Why patching alone isn’t enough

SonicWall SMA appliances and firewalls are frequent targets for attackers, whether through zero-day exploits or old, known vulnerabilities.

CVE-2026-15409 and CVE-2026-15410 impact the SMA6210, SMA7210, and SMA8200v models. Affected firmware versions include:

  • 12.4.3-03245The spokesperson stressed that “patching alone is not sufficient. Even after applying the update, we strongly recommend reviewing logs for indicators of compromise and following the guidance in our KB article closely.”Credit for discovering and reporting these vulnerabilities goes to Adam Babis of SonicWall PSIRT.Update (July 15, 2026, 02:30 a.m. ET):In an updated security advisory, SonicWall also credited Sean Koessel and Steven Adair, researchers and co-founders of Volexity, for advancing the PSIRT investigation and expanding the IOC list.The Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian agencies to address the vulnerabilities by July 17, 2026, and investigate whether their appliances have been exploited.
(Source: Help Net Security)

Topics

sonicwall vulnerabilities 98% firmware patching 95% active exploitation 93% indicators of compromise 91% remote code execution 89% server-side request forgery 87% affected appliances 85% customer remediation 83% security advisory 81% cisa involvement 79%