SonicWall SMA1000 Zero-Day Exploitation
SonicWall has disclosed two actively exploited zero-day vulnerabilities in SMA1000 secure remote access appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, both flaws carry a combined CVSS 10.0 severity rating. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities catalog on July 14, 2026, giving federal agencies until July 17, 2026, to patch or discontinue use.
What Happened: SonicWall SMA1000 Zero-Day Exploitation Confirmed in Active Attacks
On July 14, 2026, SonicWall published an urgent security advisory confirming that threat actors have been exploiting two vulnerabilities in SMA1000 appliances in zero-day attacks. SonicWall PSIRT investigated multiple incidents before confirming active exploitation. The vendor strongly urges customers to upgrade to patched hotfix releases immediately.
Furthermore, CISA added both CVEs to its Known Exploited Vulnerabilities catalog the same day. Consequently, federal agencies must apply mitigations by July 17, 2026, under Binding Operational Directive 26-04. The rapid timeline underscores the severity and active nature of these threats.
SonicWall has published indicators of compromise to help administrators detect potential breaches. However, the company has not disclosed whether the two vulnerabilities are being chained together in attacks. Volexity assisted SonicWall with the investigation.
Technical Details of the SonicWall SMA1000 Vulnerabilities
The two vulnerabilities affect SMA1000 models 6210, 7210, and 8200v. They impact specific platform-hotfix releases. SonicWall has released fixes in versions 12.4.3-03453 and 12.5.0-02835.
CVE-2026-15409: Server-Side Request Forgery
CVE-2026-15409 is a critical server-side request forgery vulnerability in the SMA1000 Appliance Work Place interface. It carries a CVSS 10.0 rating. A remote, unauthenticated attacker can force the appliance to make requests to unintended locations. This flaw requires no authentication and exposes the appliance directly to internet-based attackers.
CVE-2026-15410: Post-Authentication Code Injection
CVE-2026-15410 is a high-severity code injection vulnerability in the Appliance Management Console. It carries a CVSS 7.2 rating. A remote authenticated administrator can execute arbitrary operating system commands. While this flaw requires admin privileges, SonicWall assigned the advisory an overall CVSS 10.0 score. This suggests the two vulnerabilities may be chained in real-world attacks.
Affected Versions
- Platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434
- Platform-hotfix releases 12.5.0-02283, 12.5.0-02624, 12.5.0-02800
Products Not Affected
The vulnerabilities do not impact SSL-VPN running on SonicWall firewalls. They also do not affect the SMA 100 Series product line.
Business and Operational Impact
SMA1000 appliances provide secure remote access for enterprise networks. An active exploitation campaign against these devices poses serious risks to organizations relying on them for remote workforce connectivity.
Immediate Risks
- Unauthorized access to internal networks via compromised remote access gateways
- Lateral movement from the appliance into connected enterprise systems
- Data exfiltration through the SSRF vector to attacker-controlled infrastructure
- Potential command execution on the appliance itself
Operational Consequences
Organizations that rely on SMA1000 for remote access face a difficult choice. Patching requires downtime for the remote access gateway. However, leaving the appliance unpatched exposes the entire network to active exploitation. SonicWall has stated there are no workarounds or mitigations other than installing the hotfixes.
Compromise Assessment Requirements
SonicWall recommends that administrators perform a full compromise assessment before trusting a patched appliance. If any indicators of compromise are found, the company advises re-imaging physical appliances or redeploying virtual appliances. Administrators must also reset all user and administrator passwords and regenerate TOTP tokens.
Mitigation and Recommendations
Organizations using SonicWall SMA1000 appliances should act immediately. The CISA patch deadline of July 17, 2026, is binding for federal agencies. Private sector organizations should treat this timeline as the maximum acceptable window.
Immediate Actions for Defenders
- Upgrade immediately: Install hotfix versions 12.4.3-03453 or 12.5.0-02835 on all affected SMA1000 appliances.
- Check for compromise: Review extraweb_access.log for requests to
/__api__/loginor/__api__/logoutwith HTTP 200 status. - Check for SSRF requests: Review extraweb_access.log for
/wsproxyrequests with suspicious host parameters and HTTP 101 status. - Check for tampering: Review ctrl-service.log for hotfix rollbacks with path traversal names.
- Check config files: Inspect
/var/lib/unit/conf.jsonfor routes to/__api__/loginor/__api__/logout, which do not exist in legitimate configurations. - Re-image if compromised: If IOCs are found, re-image physical appliances or redeploy virtual appliances rather than trusting a simple patch.
- Rotate all credentials: Change all user and administrator passwords. Reset TOTP tokens for all accounts.
Network Segmentation Guidance
Organizations should review network segmentation around SMA1000 appliances. Remote access gateways are high-value targets. Therefore, restrict management console access to authorized IP ranges. Monitor outbound connections from SMA1000 appliances for unexpected traffic patterns.
Bottom line: SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 are under active exploitation with no available workarounds. Organizations must patch by July 17, 2026, and should assume compromise until a full IOC review confirms otherwise.
Summary
| CVE ID / Incident: | CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (Code Injection, CVSS 7.2) |
| Affected Systems: | SonicWall SMA1000 models 6210, 7210, and 8200v; platform-hotfix releases 12.4.3 and 12.5.0 |
| Disclosure Date: | July 14, 2026 |
| Patch Status: | Hotfixes available: 12.4.3-03453 and 12.5.0-02835 |
| CISA KEV Date Added: | July 14, 2026 |
| CISA Patch Deadline: | July 17, 2026 (BOD 26-04) |
| Exploitation Status: | Actively exploited in the wild; zero-day attacks confirmed |
| Workarounds: | None available |
References
- SonicWall Security Advisory, “SMA1000 Security Advisory: CVE-2026-15409 and CVE-2026-15410,” July 14, 2026. https://psirt.global.sonicwall.com/ (accessed July 15, 2026).
- BleepingComputer, Abrams, L., “SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now,” July 14, 2026. https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/ (accessed July 15, 2026).
- SecurityWeek, Kovacs, E., “SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits,” July 14, 2026. https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/ (accessed July 15, 2026).
- CISA, “CISA Adds Four Known Exploited Vulnerabilities to Catalog,” Alert, July 14, 2026. https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog (accessed July 15, 2026).
- CISA, Known Exploited Vulnerabilities Catalog, “CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability” and “CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability.” https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed July 15, 2026).