SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in Tandem

SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (TL-2026-1323) is a critical-severity software vulnerability, first published 2026-07-14. It has no confirmed attribution, affects SonicWall SMA1000 (SMA6210), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 23 MITRE ATT&CK techniques (T1005, T1021, T1041), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-1323

Threat ID
TL-2026-1323
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-14
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
enterprise, government administration, financial services, health, critical infrastructure, technology
Target regions
Global
Detection rules
9
Indicators of compromise
25

Malware and tooling in SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

Malware and tooling: Darkside, SMA1000 Appliance Management Console (AMC), SMA1000 Work Place interface

SonicWall SMA1000 secure remote access appliances are under active exploitation via two chained flaws: CVE-2026-15409, a critical unauthenticated SSRF in the Work Place interface, and CVE-2026-15410, a high-severity authenticated code injection in the Management Console. SonicWall has confirmed in-the-wild exploitation and shipped hotfixes for both firmware branches.

How SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection works

On July 14, 2026, SonicWall's PSIRT disclosed and hotfixed two vulnerabilities in the SMA1000 secure mobile access appliance line (SMA6210, SMA7210, SMA8200v) that are being actively exploited together against internet-facing deployments. CVE-2026-15409 is a critical, unauthenticated Server-Side Request Forgery in the appliance's Work Place (end-user) interface: by supplying a crafted/encoded URL, a remote attacker with no credentials can force the appliance to issue requests to attacker-chosen internal or external destinations, enabling internal network reconnaissance, access to cloud metadata/instance services, or interaction with internal-only management endpoints that are otherwise unreachable from the internet. CVE-2026-15410 is a high-severity code injection flaw in the SMA1000 Appliance Management Console (AMC) that requires authenticated administrator access but allows an attacker who has reached that context to inject and execute arbitrary code/OS commands on the underlying appliance operating system. SonicWall's advisory and public reporting (Help Net Security) describe the two bugs as 'being exploited in tandem' — consistent with SonicWall's SMA1000 exploitation history, where an unauthenticated primitive (SSRF/deserialization) is used to reach or forge access to an authenticated management surface, and a post-auth code-execution bug is then used to obtain full root-level command execution and persistence on the appliance. Vulnerable firmware spans the 12.4.3.x branch (12.4.3-03245, 12.4.3-03387, 12.4.3-03434) and the 12.5.0.x branch (12.5.0-02283, 12.5.0-02624, 12.5.0-02800); SonicWall shipped hotfixes 12.4.3-03453 and 12.5.0-02835. The flaw was reported to SonicWall PSIRT by Adam Babis, and SonicWall issued an advance customer notification ahead of the public advisory. SonicWall recommends organizations that cannot confirm they were unaffected rotate all user and administrator passwords, reset TOTP/MFA tokens bound to the appliance, review authentication and management-console logs for indicators of compromise, and re-image/re-deploy any appliance where compromise is suspected or confirmed. This event continues a well-established pattern for SonicWall SMA1000/SMA100 remote-access appliances, which have been repeatedly targeted by both opportunistic and ransomware-affiliated actors: a critical pre-auth deserialization RCE (CVE-2025-23006, CVSS 9.8) was actively exploited as a zero-day and patched in January 2025; an SSRF in the same Work Place interface (CVE-2025-40595, CVSS 7.2, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) was patched in the same firmware family in mid-2025; and a local privilege-escalation flaw in the AMC (CVE-2025-40602) was observed chained with CVE-2025-23006 to achieve unauthenticated root-level RCE, later added to CISA's Known Exploited Vulnerabilities catalog in December 2025. Internet-facing exposure of SMA1000 appliances has been tracked by Shadowserver at roughly 950+ hosts at various points during this exploitation history, and ransomware groups (e.g., DarkSide) have historically favored SonicWall SMA100/SMA1000 appliances as an initial-access vector. No CVSS score, formal CWE mapping, or public IOC set (attacker IPs, malware, C2) has been published by SonicWall or third parties for CVE-2026-15409/CVE-2026-15410 as of this writing; defenders should treat any unexplained AMC configuration change, new local/administrator account, or anomalous outbound request originating from the Work Place interface on unpatched SMA1000 appliances as a potential indicator of exploitation.

MITRE ATT&CK techniques used in TL-2026-1323

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols; T1090 Proxy

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1078 Valid Accounts; T1098 Account Manipulation

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1490 Inhibit System Recovery

Credential Access

T1552 Unsecured Credentials; T1556 Modify Authentication Process

Resource Development

T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

  • SonicWall — SMA1000 (SMA6210)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453; 12.5.0-02835
  • SonicWall — SMA1000 (SMA7210)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453; 12.5.0-02835
  • SonicWall — SMA1000 (SMA8200v)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453; 12.5.0-02835

Remediation for SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

Patches

  • 12.4.3-03453 (platform hotfix, 12.4.3.x branch)
  • 12.5.0-02835 (platform hotfix, 12.5.0.x branch)

Immediate actions

  • Apply SonicWall hotfix 12.4.3-03453 (12.4.3.x branch) or 12.5.0-02835 (12.5.0.x branch) to all SMA6210/SMA7210/SMA8200v appliances immediately
  • Restrict internet exposure of the SMA1000 Work Place interface and Appliance Management Console (AMC) to trusted source IPs or a VPN-only management path
  • Review Work Place interface access logs and AMC administrative logs for anomalous requests, unexpected outbound connections, or unauthorized configuration changes
  • Rotate all end-user and administrator passwords for the appliance
  • Reset TOTP/MFA seeds bound to the appliance for all users and administrators

Workarounds

  • No official workaround published; restricting Work Place/AMC exposure to trusted networks reduces but does not eliminate risk pending patch

Longer-term hardening

  • Deploy network-level monitoring/EDR-equivalent telemetry for SMA1000 appliance management-plane traffic where supported
  • Adopt a patch-on-disclosure SLA for internet-facing SonicWall SMA appliances given the vendor's repeated zero-day exploitation history
  • Segment SMA1000 appliances from sensitive internal networks to limit SSRF blast radius (e.g., cloud metadata endpoints, internal-only APIs)
  • Enroll affected appliance serials in SonicWall's security notification program for expedited advisory delivery

CVEs associated with SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

CVE-2026-15409, CVE-2026-15410

Weaknesses (CWE) in SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

CWE-918, CWE-94

Timeline of SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

  • SonicWall patches CVE-2025-23006, a critical (CVSS 9.8) pre-authentication deserialization RCE in SMA1000, after evidence of exploitation surfaced (build 12.4.3-02854) — the first in a pattern of actively exploited SMA1000 zero-days.
  • SonicWall publishes SNWLID-2025-0010 for CVE-2025-40595, an unauthenticated SSRF in the SMA1000 Work Place interface (CVSS 7.2), patched in 12.4.3-02963 — the same interface later affected by CVE-2026-15409.
  • CISA adds SonicWall SMA1000 flaw CVE-2025-40602 (AMC local privilege escalation, chained with CVE-2025-23006 for unauthenticated root RCE) to the Known Exploited Vulnerabilities catalog.
  • SonicWall advises affected organizations to reset user/administrator passwords, reset TOTP tokens, review logs for indicators of compromise, and re-image appliances where compromise is confirmed.
  • SonicWall releases hotfix builds 12.4.3-03453 and 12.5.0-02835 resolving both CVE-2026-15409 and CVE-2026-15410 for SMA6210, SMA7210, and SMA8200v appliances.
  • SonicWall and Help Net Security publicly disclose that CVE-2026-15409 (critical SSRF) and CVE-2026-15410 (high-severity code injection) are being actively exploited in tandem against SMA1000 appliances.
  • SonicWall PSIRT credits researcher Adam Babis with reporting the SSRF (CVE-2026-15409) and code injection (CVE-2026-15410) issues in the SMA1000 Work Place interface and Management Console.
  • SonicWall issues an advance customer notification ahead of public disclosure, alerting SMA1000 administrators to active exploitation of two chained vulnerabilities.

Sources cited for SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

Threats related to SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection

Detection coverage for TL-2026-1323

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1323 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats