SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. While CVE-2026-15410 requires administrator privileges, SonicWall assigned the advisory an overall CVSS score of 10.0. SonicWall says it investigated multiple incidents and confirmed that both vulnerabilities are being actively exploited. "SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," SonicWall warned. "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities" However, the company has not disclosed whether attackers are chaining them together. BleepingComputer has contacted SonicWall to clarify the attacks and will update this story if we receive a response. The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix ...
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
BleepingComputer
·Lawrence Abrams
·Published Jul 14, 2026
·Updated
Affected Software
2 affected components
SonicWall SMA1000 Appliance Work Place interface=6210, =7210, =8200v, >=12.4.3-03245<12.4.3-03453, >=12.4.3-03387<12.4.3-03453, >=12.4.3-03434<12.4.3-03453, >=12.5.0-02283<12.5.0-02835, >=12.5.0-02624<12.5.0-02835, >=12.5.0-02800<12.5.0-02835
SonicWall SMA1000 Appliance Management Console=6210, =7210, =8200v, >=12.4.3-03245<12.4.3-03453, >=12.4.3-03387<12.4.3-03453, >=12.4.3-03434<12.4.3-03453, >=12.5.0-02283<12.5.0-02835, >=12.5.0-02624<12.5.0-02835, >=12.5.0-02800<12.5.0-02835
Frequently Asked Questions
1
What vulnerabilities are being exploited in the SonicWall SMA1000?
The vulnerabilities exploited are CVE-2026-15409 and CVE-2026-15410.
2
What is the severity of the vulnerability CVE-2026-15409?
CVE-2026-15409 has a critical severity rating with a CVSS score of 10.0.
3
What type of attack do the exploited vulnerabilities relate to?
The vulnerabilities relate to zero-day attacks, specifically a server-side request forgery (SSRF) issue.
4
What action does SonicWall recommend for users of the SMA1000?
SonicWall urges customers to install the newly released security updates immediately.
5
Which products are affected by these vulnerabilities?
The affected products include the SonicWall SMA1000 Appliance Work Place interface and the SonicWall SMA1000 Appliance Management Console.