SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in Tandem
SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (TL-2026-1323) is a critical-severity software vulnerability, first published 2026-07-14. It has no confirmed attribution, affects SonicWall SMA1000 (SMA6210), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 23 MITRE ATT&CK techniques (T1005, T1021, T1041), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-1323
- Threat ID
- TL-2026-1323
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- enterprise, government administration, financial services, health, critical infrastructure, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
Malware and tooling: Darkside, SMA1000 Appliance Management Console (AMC), SMA1000 Work Place interface
SonicWall SMA1000 secure remote access appliances are under active exploitation via two chained flaws: CVE-2026-15409, a critical unauthenticated SSRF in the Work Place interface, and CVE-2026-15410, a high-severity authenticated code injection in the Management Console. SonicWall has confirmed in-the-wild exploitation and shipped hotfixes for both firmware branches.
How SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection works
On July 14, 2026, SonicWall's PSIRT disclosed and hotfixed two vulnerabilities in the SMA1000 secure mobile access appliance line (SMA6210, SMA7210, SMA8200v) that are being actively exploited together against internet-facing deployments. CVE-2026-15409 is a critical, unauthenticated Server-Side Request Forgery in the appliance's Work Place (end-user) interface: by supplying a crafted/encoded URL, a remote attacker with no credentials can force the appliance to issue requests to attacker-chosen internal or external destinations, enabling internal network reconnaissance, access to cloud metadata/instance services, or interaction with internal-only management endpoints that are otherwise unreachable from the internet. CVE-2026-15410 is a high-severity code injection flaw in the SMA1000 Appliance Management Console (AMC) that requires authenticated administrator access but allows an attacker who has reached that context to inject and execute arbitrary code/OS commands on the underlying appliance operating system. SonicWall's advisory and public reporting (Help Net Security) describe the two bugs as 'being exploited in tandem' — consistent with SonicWall's SMA1000 exploitation history, where an unauthenticated primitive (SSRF/deserialization) is used to reach or forge access to an authenticated management surface, and a post-auth code-execution bug is then used to obtain full root-level command execution and persistence on the appliance. Vulnerable firmware spans the 12.4.3.x branch (12.4.3-03245, 12.4.3-03387, 12.4.3-03434) and the 12.5.0.x branch (12.5.0-02283, 12.5.0-02624, 12.5.0-02800); SonicWall shipped hotfixes 12.4.3-03453 and 12.5.0-02835. The flaw was reported to SonicWall PSIRT by Adam Babis, and SonicWall issued an advance customer notification ahead of the public advisory. SonicWall recommends organizations that cannot confirm they were unaffected rotate all user and administrator passwords, reset TOTP/MFA tokens bound to the appliance, review authentication and management-console logs for indicators of compromise, and re-image/re-deploy any appliance where compromise is suspected or confirmed. This event continues a well-established pattern for SonicWall SMA1000/SMA100 remote-access appliances, which have been repeatedly targeted by both opportunistic and ransomware-affiliated actors: a critical pre-auth deserialization RCE (CVE-2025-23006, CVSS 9.8) was actively exploited as a zero-day and patched in January 2025; an SSRF in the same Work Place interface (CVE-2025-40595, CVSS 7.2, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) was patched in the same firmware family in mid-2025; and a local privilege-escalation flaw in the AMC (CVE-2025-40602) was observed chained with CVE-2025-23006 to achieve unauthenticated root-level RCE, later added to CISA's Known Exploited Vulnerabilities catalog in December 2025. Internet-facing exposure of SMA1000 appliances has been tracked by Shadowserver at roughly 950+ hosts at various points during this exploitation history, and ransomware groups (e.g., DarkSide) have historically favored SonicWall SMA100/SMA1000 appliances as an initial-access vector. No CVSS score, formal CWE mapping, or public IOC set (attacker IPs, malware, C2) has been published by SonicWall or third parties for CVE-2026-15409/CVE-2026-15410 as of this writing; defenders should treat any unexplained AMC configuration change, new local/administrator account, or anomalous outbound request originating from the Work Place interface on unpatched SMA1000 appliances as a potential indicator of exploitation.
MITRE ATT&CK techniques used in TL-2026-1323
Collection
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Web Protocols; T1090 Proxy
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
T1078 Valid Accounts; T1098 Account Manipulation
Defense Evasion
T1211 Exploitation for Stealth
Impact
Credential Access
T1552 Unsecured Credentials; T1556 Modify Authentication Process
Resource Development
T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
defense-impairment
Affected products and versions in SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
- SonicWall — SMA1000 (SMA6210)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453; 12.5.0-02835 - SonicWall — SMA1000 (SMA7210)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453; 12.5.0-02835 - SonicWall — SMA1000 (SMA8200v)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453; 12.5.0-02835
Remediation for SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
Patches
- 12.4.3-03453 (platform hotfix, 12.4.3.x branch)
- 12.5.0-02835 (platform hotfix, 12.5.0.x branch)
Immediate actions
- Apply SonicWall hotfix 12.4.3-03453 (12.4.3.x branch) or 12.5.0-02835 (12.5.0.x branch) to all SMA6210/SMA7210/SMA8200v appliances immediately
- Restrict internet exposure of the SMA1000 Work Place interface and Appliance Management Console (AMC) to trusted source IPs or a VPN-only management path
- Review Work Place interface access logs and AMC administrative logs for anomalous requests, unexpected outbound connections, or unauthorized configuration changes
- Rotate all end-user and administrator passwords for the appliance
- Reset TOTP/MFA seeds bound to the appliance for all users and administrators
Workarounds
- No official workaround published; restricting Work Place/AMC exposure to trusted networks reduces but does not eliminate risk pending patch
Longer-term hardening
- Deploy network-level monitoring/EDR-equivalent telemetry for SMA1000 appliance management-plane traffic where supported
- Adopt a patch-on-disclosure SLA for internet-facing SonicWall SMA appliances given the vendor's repeated zero-day exploitation history
- Segment SMA1000 appliances from sensitive internal networks to limit SSRF blast radius (e.g., cloud metadata endpoints, internal-only APIs)
- Enroll affected appliance serials in SonicWall's security notification program for expedited advisory delivery
CVEs associated with SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
Weaknesses (CWE) in SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
CWE-918, CWE-94
Timeline of SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
- SonicWall patches CVE-2025-23006, a critical (CVSS 9.8) pre-authentication deserialization RCE in SMA1000, after evidence of exploitation surfaced (build 12.4.3-02854) — the first in a pattern of actively exploited SMA1000 zero-days.
- SonicWall publishes SNWLID-2025-0010 for CVE-2025-40595, an unauthenticated SSRF in the SMA1000 Work Place interface (CVSS 7.2), patched in 12.4.3-02963 — the same interface later affected by CVE-2026-15409.
- CISA adds SonicWall SMA1000 flaw CVE-2025-40602 (AMC local privilege escalation, chained with CVE-2025-23006 for unauthenticated root RCE) to the Known Exploited Vulnerabilities catalog.
- SonicWall advises affected organizations to reset user/administrator passwords, reset TOTP tokens, review logs for indicators of compromise, and re-image appliances where compromise is confirmed.
- SonicWall releases hotfix builds 12.4.3-03453 and 12.5.0-02835 resolving both CVE-2026-15409 and CVE-2026-15410 for SMA6210, SMA7210, and SMA8200v appliances.
- SonicWall and Help Net Security publicly disclose that CVE-2026-15409 (critical SSRF) and CVE-2026-15410 (high-severity code injection) are being actively exploited in tandem against SMA1000 appliances.
- SonicWall PSIRT credits researcher Adam Babis with reporting the SSRF (CVE-2026-15409) and code injection (CVE-2026-15410) issues in the SMA1000 Work Place interface and Management Console.
- SonicWall issues an advance customer notification ahead of public disclosure, alerting SMA1000 administrators to active exploitation of two chained vulnerabilities.
Sources cited for SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
- SonicWall SMA attacks via CVE-2026-15409, CVE-2026-15410
- SonicWall PSIRT Security Advisories
- Sonicwall warns of new SMA1000 zero-day exploited in attacks
- SonicWall warns hackers targeting critical vulnerability in SMA 1000 series appliances
- SonicWall SMA1000 Vulnerability Let Attackers to Exploit Encoded URLs To Gain Internal Systems Access Remotely
- SMA 1000 Series affected by Encoded URL SSRF Vulnerability (SNWLID-2025-0010)
- Multiple Vulnerabilities in SonicWall SMA1000 Series
- U.S. CISA adds Cisco, SonicWall, and ASUS flaws to its Known Exploited Vulnerabilities catalog
Threats related to SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)
Detection coverage for TL-2026-1323
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1323 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.