Vulnerabilities

SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits

SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution.

SonicWall vulnerability

SonicWall is urging customers to immediately update SMA1000 secure remote access appliances, which are being targeted by threat actors via two new zero-day vulnerabilities. 

The vulnerabilities are tracked as CVE-2026-15409 and CVE-2026-15410, and they affect SMA1000 versions 6210, 7210, and 8200v. Enterprises using these products have been instructed to update to hotfix releases 12.4.3-03453 or 12.5.0-02835.

CVE-2026-15409 has been described as a critical server-side request forgery (SSRF) issue affecting the Appliance Work Place interface. It allows a remote, unauthenticated attacker to cause the targeted appliance to “make requests to unintended locations”.

CVE-2026-15410 is a high-severity code injection issue affecting the Appliance Management Console (AMC), and it can allow an attacker with admin privileges to execute arbitrary OS commands. 

“SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory,” SonicWall said in its advisory.

It’s unclear who is behind the zero-day exploitation, but the vendor has shared some IoCs to help enterprises detect potential attacks. Based on the company’s brief description, the two vulnerabilities may be chained.

Advertisement. Scroll to continue reading.

Volexity has been credited with assisting SonicWall’s investigation into the zero-day attacks, but the cybersecurity firm has yet to release any details. 

CISA added CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, urging government agencies to address them by July 17. 

It’s not uncommon for threat actors, including profit-driven cybercriminals, to exploit vulnerabilities in SonicWall products. CISA’s KEV catalog currently includes 17 flaws, including ones affecting SMA1000 appliances.

Related: Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Related: Organizations Warned of Exploited Joomla Extension Vulnerabilities

Related: BlueHammer Vulnerability Exploited in Ransomware Attacks

Related: Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

Related Content

Artificial Intelligence

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Vulnerabilities

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

Vulnerabilities

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.

Vulnerabilities

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.

Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

Vulnerabilities

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

Vulnerabilities

The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.

Vulnerabilities

Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version