• News/
  • bleepingcomputer-20260714212324

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

BleepingComputer
·
Lawrence Abrams
·
Published Jul 14, 2026
·
Updated

SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. While CVE-2026-15410 requires administrator privileges, SonicWall assigned the advisory an overall CVSS score of 10.0. SonicWall says it investigated multiple incidents and confirmed that both vulnerabilities are being actively exploited. "SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," SonicWall warned. "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities" However, the company has not disclosed whether attackers are chaining them together. BleepingComputer has contacted SonicWall to clarify the attacks and will update this story if we receive a response. The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix ...

Read full article

Affected Software

2 affected components
SonicWall SMA1000 Appliance Work Place interface=6210, =7210, =8200v, >=12.4.3-03245<12.4.3-03453, >=12.4.3-03387<12.4.3-03453, >=12.4.3-03434<12.4.3-03453, >=12.5.0-02283<12.5.0-02835, >=12.5.0-02624<12.5.0-02835, >=12.5.0-02800<12.5.0-02835
SonicWall SMA1000 Appliance Management Console=6210, =7210, =8200v, >=12.4.3-03245<12.4.3-03453, >=12.4.3-03387<12.4.3-03453, >=12.4.3-03434<12.4.3-03453, >=12.5.0-02283<12.5.0-02835, >=12.5.0-02624<12.5.0-02835, >=12.5.0-02800<12.5.0-02835
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are being exploited in the SonicWall SMA1000?

The vulnerabilities exploited are CVE-2026-15409 and CVE-2026-15410.

2

What is the severity of the vulnerability CVE-2026-15409?

CVE-2026-15409 has a critical severity rating with a CVSS score of 10.0.

3

What type of attack do the exploited vulnerabilities relate to?

The vulnerabilities relate to zero-day attacks, specifically a server-side request forgery (SSRF) issue.

4

What action does SonicWall recommend for users of the SMA1000?

SonicWall urges customers to install the newly released security updates immediately.

5

Which products are affected by these vulnerabilities?

The affected products include the SonicWall SMA1000 Appliance Work Place interface and the SonicWall SMA1000 Appliance Management Console.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203