Skip to content

SonicWall SMA 1000: Two Zero-Days Under Active Exploitation

The Point: Two zero-days in SonicWall SMA 1000 are being actively exploited; one enables command execution with admin privileges.

SonicWall warns of active attacks against two unknown security vulnerabilities in the Secure Mobile Access (SMA) 1000 series. One of them enables arbitrary command execution with administrator rights.

The affected devices are SonicWall SMA 1000 appliances, which are typically deployed in the VPN-based remote access infrastructure of enterprises. The company confirms that both vulnerabilities are already being exploited in the field.

The first identified vulnerability is designated CVE-2026-15409 and receives a CVSS rating of 10.0. It is a Server-Side Request Forgery (SSRF) that allows an unauthenticated attacker to remotely manipulate the appliance. Details on the second vulnerability have not yet been fully communicated.

For CISOs, timely patching is critical, as the SMA series frequently functions as a direct Internet access channel and is thus exposed to attackers. The combination of zero-day status and active exploitation requires immediate attention and mitigation regardless of availability windows.


Source: thehackernews.com · Published 15 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.

Share on: