SonicWall warns that attackers are exploiting two SMA1000 vulnerabilities tracked as CVE-2026-15409 and CVE-2026-15410 in zero-day assaults and urges prospects to put in newly launched safety updates.
CVE-2026-15409 is a essential (CVSS 10.0) server-side request forgery (SSRF) vulnerability within the office interface of the SMA1000 equipment that permits a distant, unauthenticated attacker to pressure the equipment to make requests to unintended places.
CVE-2026-15410 is a high-severity post-authentication code injection (CVSS 7.2) flaw within the SMA1000 Equipment Administration Console that would permit a distant authenticated administrator to execute arbitrary working system instructions.
Though CVE-2026-15410 requires administrative privileges, SonicWall assigned this advisory an total CVSS rating of 10.0.
SonicWall says it has investigated a number of incidents and confirmed that each vulnerabilities are being actively exploited.
“SonicWall PSIRT has investigated a number of cases demonstrating lively exploitation of the vulnerabilities described on this advisory,” SonicWall warned.
“We strongly encourage prospects to improve to the hotfix launch as quickly as doable to repair these vulnerabilities.”
Nevertheless, the corporate didn’t say whether or not the attackers had been chaining them collectively. BleepingComputer has reached out to SonicWall for clarification on the assault and can replace this text if we obtain a response.
This vulnerability exists in platform hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. The repair is accessible in platform hotfix variations 12.4.3-03453 and 12.5.0-02835 and later releases.
In keeping with SonicWall, this vulnerability doesn’t have an effect on SSL-VPN or the SMA 100 collection product line working on SonicWall firewalls.
The corporate additionally shared indicators of compromise (IOCs) that directors can use to find out if an equipment has been compromised.
- If extraweb_access.log reveals a request to /__api__/login or /__api__/logout with an HTTP 200 standing
- If extraweb_access.log reveals a request to /wsproxy with a suspicious host parameter with HTTP standing 101
- ctrl-service.log lists hotfix rollbacks with path traversal names
- /var/lib/unit/conf.json accommodates routes /__api__/login or /__api__/logout (these URIs don’t exist within the canonical configuration)
SonicWall extremely recommends that you just improve to the most recent hotfix launch and run an evaluation to find out if any of the above IOCs are current.
If a tool is set to have been compromised, the corporate advises directors to reimage the bodily equipment or redeploy the digital equipment, change all person and administrator passwords, and reset TOTP tokens.
SonicWall additionally notes that there aren’t any workarounds or mitigations for these flaws aside from putting in hotfixes.
The U.S. Cybersecurity and Infrastructure Safety Company (CISA) added each vulnerabilities to its Identified Exploited Vulnerabilities (KEV) catalog and confirmed that they’re being actively exploited in assaults.
Federal companies have till July 17, 2026 to guard affected programs underneath Binding Working Order (BOD) 26-04 or take away the product from use if mitigations can’t be utilized.

Safety groups doc 54% of profitable assaults and situation a warning on solely 14%. The remaining strikes invisibly by the surroundings.
Picus’ whitepaper reveals how one can take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
