CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

July 15, 2026

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.

The vulnerabilities are listed below:

  • CVE-2026-15409 (CVSS score: 10.0) – A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location.
  • CVE-2026-15410 (CVSS score: 7.2) – A post-authentication code injection vulnerability rooted in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.

SonicWall said it has “investigated multiple cases indicating the active exploitation of the vulnerabilities,” urging customers to apply the fixes as soon as possible. The patches are available in versions 12.4.3-03453 (platform-hotfix) and higher, and 12.5.0-02835 (platform-hotfix) and higher.

Users are also urged to perform a thorough forensic analysis of the system to determine the presence of any indicators of compromise (IoCs) associated with exploitation. Indicators include requests to /__api__/login or /__api__/logout with http 200 status in extraweb_access.log, requests to /wsproxy with suspicious host parameters with 101 http status, hotfix rollbacks with path traversal names in ctrl-service.log, and routes for /__api__/login or /__api__/logout in /var/lib/unit/conf.json. If indicators are present, it’s advised to re-image physical appliances or redeploy virtual appliances, change user and administrator passwords, and reset time-based one-time password tokens.

Adam Babis of SonicWall’s product security incident response team (PSIRT) discovered and reported the flaws. SonicWall also acknowledged contributions from Volexity’s Sean Koessel and Steven Adair. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply fixes by July 17, 2026.

CVEs: CVE-2026-15409, CVE-2026-15410

Companies: SonicWall, Volexity, CISA

Products: SonicWall SMA 1000