SonicWall has confirmed attackers are actively exploiting two previously unknown flaws in its SMA1000
appliances, which organisations use to give staff secure remote access to internal systems. The most
severe flaw carries the maximum possible risk score and needs no login to exploit. Fixes are available
now; upgrade immediately and check appliances for the signs of compromise listed in this advisory.
1.Vulnerability Details
SonicWall PSIRT confirmed active exploitation of both flaws as zero-days. Neither affects SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.
- CVE-2026-15409 (CVSS 10.0) Server-side request forgery, CWE-918, in the SMA1000 Appliance Work Place interface. A remote attacker with no login can force the appliance to make requests to unintended locations. Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
- CVE-2026-15410 (CVSS 7.2) Post-authentication code injection, CWE-94, in the SMA1000 Appliance Management Console (AMC). A remote attacker authenticated as administrator can execute arbitrary OS commands. Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H.
2. Observed Activity
Both flaws were exploited before fixes existed. SonicWall released the hotfixes publicly on 14 July 2026 after notifying affected customers in advance.
- Confirmed exploitation (14 July 2026) SonicWall PSIRT investigated multiple cases indicating active exploitation of CVE-2026-15409 and CVE-2026-15410. Help Net Security reports the two flaws are used in tandem in attacks observed so far; SonicWall has not confirmed chaining.
- CISA KEV listing (14 July 2026) CISA added both CVEs to the Known Exploited Vulnerabilities catalogue. US federal agencies must remediate by 17 July 2026 under Binding Operational Directive 26-04.
- Post-compromise guidance Where indicators are present, SonicWall advises re-imaging hardware appliances or redeploying virtual ones, changing all user and administrator passwords, and resetting TOTP tokens. Volexity researchers helped identify an additional indicator during the investigation.
3. Indicators of Compromise (IOCs)
- if in extraweb_access.log are mentioned requests to /api/login or /api/logout with http 200 status
- if in extraweb_access.log are mentioned requests to /wsproxy with suspicious host parameters with 101 http status
- if in ctrl-service.log are mentioned hotfix rollbacks with path traversal names
- if /var/lib/unit/conf.json contains routes for /api/login or /api/logout (these URIs do not exist in legitimate configuration)
4. Recommendations
- Identify SMA1000 appliances, models 6210, 7210, and 8200v, running any affected platform-hotfix version listed in this advisory.
- Upgrade to platform-hotfix 12.4.3-03453 or 12.5.0-02835 from mysonicwall.com now; SonicWall confirms no workaround exists.
- Review extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json for the indicators in this advisory; patching alone does not remove an existing compromise.
- If indicators are present, re-image hardware appliances or redeploy virtual ones, change all user and administrator passwords, and reset TOTP tokens.
6. Sources
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-202
6-15410/
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.