SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days

SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code (TL-2026-1335), also tracked as SNWLID-2026-0008, is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-14. It has no confirmed attribution, affects SonicWall SMA1000 (SMA6210), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 17 MITRE ATT&CK techniques (T1005, T1016, T1041), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-1335

Threat ID
TL-2026-1335
Also known as
SNWLID-2026-0008
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-14
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, managedsecurityservices, enterprise, criticalinfrastructure
Target regions
North America, Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

Malware and tooling: SMA1000 Appliance Management Console (AMC), SMA1000 Work Place interface

SonicWall disclosed two SMA1000 vulnerabilities under active zero-day exploitation: an unauthenticated critical SSRF in the Work Place interface (CVE-2026-15409, CVSS 10.0) and a post-authentication OS command injection in the Management Console (CVE-2026-15410, CVSS 7.2), being chained in tandem against SMA6210/7210/8200v appliances.

How SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code works

SonicWall's PSIRT issued advisory SNWLID-2026-0008 for two vulnerabilities in the SMA1000 Secure Mobile Access appliance line (models SMA6210, SMA7210, SMA8200v), confirming multiple cases of active zero-day exploitation observed prior to public disclosure on 2026-07-14.

CVE-2026-15409 is a critical (CVSS 3.1 base score 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) server-side request forgery (CWE-918) in the SMA1000 Work Place interface. An unauthenticated remote attacker sends a specially crafted, URL-encoded request that causes the appliance to make requests to an unintended internal or external location, effectively giving the attacker a foothold to reach internal management surfaces from the unauthenticated Work Place portal.

CVE-2026-15410 is a high-severity (CVSS 3.1 base score 7.2, AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) post-authentication improper control of code generation (code injection, CWE-94) in the SMA1000 Appliance Management Console (AMC). Under specific conditions, a remote attacker already holding administrator-level authentication to the AMC can inject and execute arbitrary operating system commands, achieving full remote code execution on the appliance.

In observed attacks the two flaws are being exploited in tandem: the SSRF in the unauthenticated Work Place interface is used to reach or manipulate the AMC context, after which the code-injection primitive is used to execute OS commands and take full control of the appliance. Because SMA1000 devices are internet-facing SSL-VPN gateways brokering access into enterprise, government, and MSSP networks, a compromised appliance gives an attacker a durable foothold for lateral movement into the protected internal network.

SonicWall's guidance states that patching alone is not sufficient for appliances that show indicators of compromise: affected organizations should review extraweb_access.log and ctrl-service.log for the documented log signatures, re-image (physical) or redeploy (virtual) any appliance showing IOC hits, and reset all user/administrator credentials and TOTP tokens. No workaround exists short of patching; Shadowserver identified more than 950 internet-exposed SMA1000 appliances at time of disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog and set a federal remediation deadline of 2026-07-17 under BOD 26-04.

MITRE ATT&CK techniques used in TL-2026-1335

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Defense Evasion

T1070 Indicator Removal; T1211 Exploitation for Stealth

Command and Control

T1071 Application Layer Protocol

Persistence

T1078 Valid Accounts

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Credential Access

T1556 Modify Authentication Process

Resource Development

T1587.004 Exploits

Reconnaissance

T1595 Active Scanning

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

  • SonicWall — SMA1000 (SMA6210)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453; 12.5.0-02835
  • SonicWall — SMA1000 (SMA7210)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453; 12.5.0-02835
  • SonicWall — SMA1000 (SMA8200v)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453; 12.5.0-02835

Remediation for SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

Patches

  • Platform-hotfix 12.4.3-03453
  • Platform-hotfix 12.5.0-02835 (and later releases)

Immediate actions

  • Apply platform-hotfix 12.4.3-03453 or 12.5.0-02835 (or later) via MySonicWall / SonicWall Support
  • Review extraweb_access.log for requests to /__api__/login or /__api__/logout returning HTTP 200
  • Review extraweb_access.log for requests to /wsproxy with suspicious host parameters returning HTTP 101
  • Review ctrl-service.log for hotfix rollbacks using path-traversal filenames
  • Inspect /var/lib/unit/conf.json for unauthorized routes referencing /__api__/login or /__api__/logout
  • If any IOC is present, re-image physical appliances or redeploy virtual appliances rather than trusting an in-place patch

Longer-term hardening

  • Reset all user and administrator credentials on affected SMA1000 appliances
  • Reset all TOTP/MFA tokens issued by the appliance
  • Restrict AMC access to trusted management networks; remove AMC from direct internet exposure
  • Monitor SMA1000 logs continuously for the documented IOC patterns
  • Track CISA KEV and SonicWall PSIRT advisories for this product line given repeated zero-day history

CVEs associated with SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

CVE-2026-15409, CVE-2026-15410

Weaknesses (CWE) in SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

CWE-918, CWE-94

Timeline of SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

  • SonicWall sends advance alert to customers instructing them to contact SonicWall Support for hotfixes ahead of public advisory publication.
  • Shadowserver identifies more than 950 internet-exposed SMA1000 appliances at the time of disclosure, noting some may already be patched.
  • CISA adds CVE-2026-15409 and CVE-2026-15410 to the Known Exploited Vulnerabilities catalog.
  • SonicWall states patching alone is not sufficient for appliances showing indicators of compromise and instructs affected organizations to re-image or redeploy compromised appliances and reset all credentials and TOTP tokens.
  • SonicWall releases platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 fixing both vulnerabilities.
  • Help Net Security and other outlets report the SSRF and code-injection flaws are being exploited together in active attacks, with the unauthenticated SSRF used to reach the authenticated Management Console context before the code-injection primitive executes OS commands.
  • SonicWall credits internal PSIRT researcher Adam Babis with discovering and reporting both CVE-2026-15409 and CVE-2026-15410; no external threat-actor attribution has been published.
  • SonicWall publishes PSIRT advisory SNWLID-2026-0008 disclosing CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection, CVSS 7.2).
  • SonicWall PSIRT confirms multiple cases of active zero-day exploitation of CVE-2026-15409 and CVE-2026-15410 against SMA1000 appliances.
  • CISA Binding Operational Directive 26-04 deadline for federal agencies to remediate both CVEs.

Sources cited for SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

Threats related to SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code

Detection coverage for TL-2026-1335

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1335 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats