SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code (TL-2026-1335), also tracked as SNWLID-2026-0008, is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-14. It has no confirmed attribution, affects SonicWall SMA1000 (SMA6210), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 17 MITRE ATT&CK techniques (T1005, T1016, T1041), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-1335
- Threat ID
- TL-2026-1335
- Also known as
- SNWLID-2026-0008
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, managedsecurityservices, enterprise, criticalinfrastructure
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
Malware and tooling: SMA1000 Appliance Management Console (AMC), SMA1000 Work Place interface
SonicWall disclosed two SMA1000 vulnerabilities under active zero-day exploitation: an unauthenticated critical SSRF in the Work Place interface (CVE-2026-15409, CVSS 10.0) and a post-authentication OS command injection in the Management Console (CVE-2026-15410, CVSS 7.2), being chained in tandem against SMA6210/7210/8200v appliances.
How SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code works
SonicWall's PSIRT issued advisory SNWLID-2026-0008 for two vulnerabilities in the SMA1000 Secure Mobile Access appliance line (models SMA6210, SMA7210, SMA8200v), confirming multiple cases of active zero-day exploitation observed prior to public disclosure on 2026-07-14.
CVE-2026-15409 is a critical (CVSS 3.1 base score 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) server-side request forgery (CWE-918) in the SMA1000 Work Place interface. An unauthenticated remote attacker sends a specially crafted, URL-encoded request that causes the appliance to make requests to an unintended internal or external location, effectively giving the attacker a foothold to reach internal management surfaces from the unauthenticated Work Place portal.
CVE-2026-15410 is a high-severity (CVSS 3.1 base score 7.2, AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) post-authentication improper control of code generation (code injection, CWE-94) in the SMA1000 Appliance Management Console (AMC). Under specific conditions, a remote attacker already holding administrator-level authentication to the AMC can inject and execute arbitrary operating system commands, achieving full remote code execution on the appliance.
In observed attacks the two flaws are being exploited in tandem: the SSRF in the unauthenticated Work Place interface is used to reach or manipulate the AMC context, after which the code-injection primitive is used to execute OS commands and take full control of the appliance. Because SMA1000 devices are internet-facing SSL-VPN gateways brokering access into enterprise, government, and MSSP networks, a compromised appliance gives an attacker a durable foothold for lateral movement into the protected internal network.
SonicWall's guidance states that patching alone is not sufficient for appliances that show indicators of compromise: affected organizations should review extraweb_access.log and ctrl-service.log for the documented log signatures, re-image (physical) or redeploy (virtual) any appliance showing IOC hits, and reset all user/administrator credentials and TOTP tokens. No workaround exists short of patching; Shadowserver identified more than 950 internet-exposed SMA1000 appliances at time of disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog and set a federal remediation deadline of 2026-07-17 under BOD 26-04.
MITRE ATT&CK techniques used in TL-2026-1335
Collection
Discovery
T1016 System Network Configuration Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
T1070 Indicator Removal; T1211 Exploitation for Stealth
Command and Control
T1071 Application Layer Protocol
Persistence
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Credential Access
T1556 Modify Authentication Process
Resource Development
Reconnaissance
defense-impairment
Affected products and versions in SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
- SonicWall — SMA1000 (SMA6210)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453; 12.5.0-02835 - SonicWall — SMA1000 (SMA7210)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453; 12.5.0-02835 - SonicWall — SMA1000 (SMA8200v)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453; 12.5.0-02835
Remediation for SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
Patches
- Platform-hotfix 12.4.3-03453
- Platform-hotfix 12.5.0-02835 (and later releases)
Immediate actions
- Apply platform-hotfix 12.4.3-03453 or 12.5.0-02835 (or later) via MySonicWall / SonicWall Support
- Review extraweb_access.log for requests to /__api__/login or /__api__/logout returning HTTP 200
- Review extraweb_access.log for requests to /wsproxy with suspicious host parameters returning HTTP 101
- Review ctrl-service.log for hotfix rollbacks using path-traversal filenames
- Inspect /var/lib/unit/conf.json for unauthorized routes referencing /__api__/login or /__api__/logout
- If any IOC is present, re-image physical appliances or redeploy virtual appliances rather than trusting an in-place patch
Longer-term hardening
- Reset all user and administrator credentials on affected SMA1000 appliances
- Reset all TOTP/MFA tokens issued by the appliance
- Restrict AMC access to trusted management networks; remove AMC from direct internet exposure
- Monitor SMA1000 logs continuously for the documented IOC patterns
- Track CISA KEV and SonicWall PSIRT advisories for this product line given repeated zero-day history
CVEs associated with SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
Weaknesses (CWE) in SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
CWE-918, CWE-94
Timeline of SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
- SonicWall sends advance alert to customers instructing them to contact SonicWall Support for hotfixes ahead of public advisory publication.
- Shadowserver identifies more than 950 internet-exposed SMA1000 appliances at the time of disclosure, noting some may already be patched.
- CISA adds CVE-2026-15409 and CVE-2026-15410 to the Known Exploited Vulnerabilities catalog.
- SonicWall states patching alone is not sufficient for appliances showing indicators of compromise and instructs affected organizations to re-image or redeploy compromised appliances and reset all credentials and TOTP tokens.
- SonicWall releases platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 fixing both vulnerabilities.
- Help Net Security and other outlets report the SSRF and code-injection flaws are being exploited together in active attacks, with the unauthenticated SSRF used to reach the authenticated Management Console context before the code-injection primitive executes OS commands.
- SonicWall credits internal PSIRT researcher Adam Babis with discovering and reporting both CVE-2026-15409 and CVE-2026-15410; no external threat-actor attribution has been published.
- SonicWall publishes PSIRT advisory SNWLID-2026-0008 disclosing CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection, CVSS 7.2).
- SonicWall PSIRT confirms multiple cases of active zero-day exploitation of CVE-2026-15409 and CVE-2026-15410 against SMA1000 appliances.
- CISA Binding Operational Directive 26-04 deadline for federal agencies to remediate both CVEs.
Sources cited for SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
- SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
- SonicWall SMA1000 Vulnerability Let Attackers to Exploit Encoded URLs To Gain Internal Systems Access Remotely
- Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges
- SonicWall Edge Access Devices Hit by Zero-Day Attacks
- NVD - CVE-2026-15409
- NVD - CVE-2026-15410
- SonicWall PSIRT Advisory SNWLID-2026-0008
- CISA Known Exploited Vulnerabilities Catalog
- SonicWall SMA 1000 Series vulnerability actively exploited
Threats related to SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)
Detection coverage for TL-2026-1335
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1335 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.