Skip to content

SonicWall: Two Zero-Day Vulnerabilities in SMA1000 Actively Exploited

The point: CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 enable unauthenticated and authenticated attacks with severity 10.0; immediate patches required, no workarounds available.

SonicWall warns of two critical security vulnerabilities (CVE-2026-15409, CVE-2026-15410) in Secure Mobile Access 1000 systems that are already being actively exploited in the wild. Immediate patching is required, as the flaws directly threaten the operation of remote access gateways.

Affected are the SMA1000 models 6210, 7210, and 8200v. The vendor’s own security team (PSIRT) has documented multiple cases in which both vulnerabilities have been actively exploited. SMA 100 series and SSL VPN functionality on SonicWall firewalls are not affected.

CVE-2026-15409 is a Server-Side Request Forgery (SSRF) in the “Work Place” web interface with maximum severity (10.0). An unauthenticated attacker can force the device to send requests to internal network targets. CVE-2026-15410 is a code injection flaw in the Appliance Management Console (AMC) with severity 7.2. It requires administrator login and enables arbitrary operating system commands. SonicWall rates the combination of both flaws with a risk score of 10.0, as they could theoretically be chained together.

Affected firmware versions are 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. Patches are available in hotfix versions 12.4.3-03453 and 12.5.0-02835 and all newer versions. No workarounds exist — immediate installation is required.

Administrators should examine systems for signs of compromise: suspicious login/logout entries in extraweb_access.log with HTTP 200, /wsproxy requests with suspicious host parameters and HTTP 101, hotfix rollback entries in ctrl-service.log, and unexpectedly new API routes in /var/lib/unit/conf.json. If indicators are found, complete re-imaging of physical devices, rebuilding of virtual instances, and resetting of all passwords and TOTP keys are required.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added both CVEs to its catalog of exploited vulnerabilities. US federal agencies must patch or disable affected systems by July 17, 2026.


Source: www.it-daily.net · Published July 15, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: