Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEexploitVulnerability

SonicWall SMA1000 Zero-Day Exploitation

By ogwatermelon
July 15, 2026 4 Min Read
0
July 15, 2026

SonicWall has disclosed two actively exploited zero-day vulnerabilities in SMA1000 secure remote access appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, both flaws carry a combined CVSS 10.0 severity rating. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities catalog on July 14, 2026, giving federal agencies until July 17, 2026, to patch or discontinue use.

What Happened: SonicWall SMA1000 Zero-Day Exploitation Confirmed in Active Attacks

On July 14, 2026, SonicWall published an urgent security advisory confirming that threat actors have been exploiting two vulnerabilities in SMA1000 appliances in zero-day attacks. SonicWall PSIRT investigated multiple incidents before confirming active exploitation. The vendor strongly urges customers to upgrade to patched hotfix releases immediately.

Furthermore, CISA added both CVEs to its Known Exploited Vulnerabilities catalog the same day. Consequently, federal agencies must apply mitigations by July 17, 2026, under Binding Operational Directive 26-04. The rapid timeline underscores the severity and active nature of these threats.

SonicWall has published indicators of compromise to help administrators detect potential breaches. However, the company has not disclosed whether the two vulnerabilities are being chained together in attacks. Volexity assisted SonicWall with the investigation.

Technical Details of the SonicWall SMA1000 Vulnerabilities

The two vulnerabilities affect SMA1000 models 6210, 7210, and 8200v. They impact specific platform-hotfix releases. SonicWall has released fixes in versions 12.4.3-03453 and 12.5.0-02835.

CVE-2026-15409: Server-Side Request Forgery

CVE-2026-15409 is a critical server-side request forgery vulnerability in the SMA1000 Appliance Work Place interface. It carries a CVSS 10.0 rating. A remote, unauthenticated attacker can force the appliance to make requests to unintended locations. This flaw requires no authentication and exposes the appliance directly to internet-based attackers.

CVE-2026-15410: Post-Authentication Code Injection

CVE-2026-15410 is a high-severity code injection vulnerability in the Appliance Management Console. It carries a CVSS 7.2 rating. A remote authenticated administrator can execute arbitrary operating system commands. While this flaw requires admin privileges, SonicWall assigned the advisory an overall CVSS 10.0 score. This suggests the two vulnerabilities may be chained in real-world attacks.

Affected Versions

  • Platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434
  • Platform-hotfix releases 12.5.0-02283, 12.5.0-02624, 12.5.0-02800

Products Not Affected

The vulnerabilities do not impact SSL-VPN running on SonicWall firewalls. They also do not affect the SMA 100 Series product line.

Business and Operational Impact

SMA1000 appliances provide secure remote access for enterprise networks. An active exploitation campaign against these devices poses serious risks to organizations relying on them for remote workforce connectivity.

Immediate Risks

  • Unauthorized access to internal networks via compromised remote access gateways
  • Lateral movement from the appliance into connected enterprise systems
  • Data exfiltration through the SSRF vector to attacker-controlled infrastructure
  • Potential command execution on the appliance itself

Operational Consequences

Organizations that rely on SMA1000 for remote access face a difficult choice. Patching requires downtime for the remote access gateway. However, leaving the appliance unpatched exposes the entire network to active exploitation. SonicWall has stated there are no workarounds or mitigations other than installing the hotfixes.

Compromise Assessment Requirements

SonicWall recommends that administrators perform a full compromise assessment before trusting a patched appliance. If any indicators of compromise are found, the company advises re-imaging physical appliances or redeploying virtual appliances. Administrators must also reset all user and administrator passwords and regenerate TOTP tokens.

Mitigation and Recommendations

Organizations using SonicWall SMA1000 appliances should act immediately. The CISA patch deadline of July 17, 2026, is binding for federal agencies. Private sector organizations should treat this timeline as the maximum acceptable window.

Immediate Actions for Defenders

  1. Upgrade immediately: Install hotfix versions 12.4.3-03453 or 12.5.0-02835 on all affected SMA1000 appliances.
  2. Check for compromise: Review extraweb_access.log for requests to /__api__/login or /__api__/logout with HTTP 200 status.
  3. Check for SSRF requests: Review extraweb_access.log for /wsproxy requests with suspicious host parameters and HTTP 101 status.
  4. Check for tampering: Review ctrl-service.log for hotfix rollbacks with path traversal names.
  5. Check config files: Inspect /var/lib/unit/conf.json for routes to /__api__/login or /__api__/logout, which do not exist in legitimate configurations.
  6. Re-image if compromised: If IOCs are found, re-image physical appliances or redeploy virtual appliances rather than trusting a simple patch.
  7. Rotate all credentials: Change all user and administrator passwords. Reset TOTP tokens for all accounts.

Network Segmentation Guidance

Organizations should review network segmentation around SMA1000 appliances. Remote access gateways are high-value targets. Therefore, restrict management console access to authorized IP ranges. Monitor outbound connections from SMA1000 appliances for unexpected traffic patterns.

Bottom line: SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 are under active exploitation with no available workarounds. Organizations must patch by July 17, 2026, and should assume compromise until a full IOC review confirms otherwise.

Summary

CVE ID / Incident: CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (Code Injection, CVSS 7.2)
Affected Systems: SonicWall SMA1000 models 6210, 7210, and 8200v; platform-hotfix releases 12.4.3 and 12.5.0
Disclosure Date: July 14, 2026
Patch Status: Hotfixes available: 12.4.3-03453 and 12.5.0-02835
CISA KEV Date Added: July 14, 2026
CISA Patch Deadline: July 17, 2026 (BOD 26-04)
Exploitation Status: Actively exploited in the wild; zero-day attacks confirmed
Workarounds: None available

References

  1. SonicWall Security Advisory, “SMA1000 Security Advisory: CVE-2026-15409 and CVE-2026-15410,” July 14, 2026. https://psirt.global.sonicwall.com/ (accessed July 15, 2026).
  2. BleepingComputer, Abrams, L., “SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now,” July 14, 2026. https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/ (accessed July 15, 2026).
  3. SecurityWeek, Kovacs, E., “SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits,” July 14, 2026. https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/ (accessed July 15, 2026).
  4. CISA, “CISA Adds Four Known Exploited Vulnerabilities to Catalog,” Alert, July 14, 2026. https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog (accessed July 15, 2026).
  5. CISA, Known Exploited Vulnerabilities Catalog, “CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability” and “CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability.” https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed July 15, 2026).

Tags:

CVEExploitVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Nihon Kotsu Cyberattack Shuts Down Japan Largest Taxi Fleet

Next

Microsoft July 2026 Patch Tuesday Fixes Record 622 Flaws: Two Zero-Days Under Active Attack | SharePoint & AD FS

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.