SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem
SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409 (TL-2026-1357), also tracked as SNWLID-2026-0008, is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-15. It has no confirmed attribution, affects SonicWall SMA1000 Series (SMA6210), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 18 MITRE ATT&CK techniques (T1005, T1046, T1059.004), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-1357
- Threat ID
- TL-2026-1357
- Also known as
- SNWLID-2026-0008
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, critical-infrastructure, education, retail
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 18
SonicWall PSIRT confirmed active, in-the-wild exploitation of two SMA1000 Series zero-days: an unauthenticated SSRF in the Workplace interface (CVE-2026-15409, CVSS 10.0) and a post-authentication OS command injection in the Appliance Management Console (CVE-2026-15410, CVSS 7.2). Attackers have been observed chaining the two flaws together against SMA6210, SMA7210, and SMA8200v appliances running platform-hotfix 12.4.3 or 12.5.0. Volexity assisted SonicWall's investigation and IOC development.
How SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409 works
On 2026-07-14, SonicWall PSIRT published advisory SNWLID-2026-0008 disclosing two zero-day vulnerabilities in the SMA1000 Series Secure Mobile Access appliance line that are being actively exploited against customer environments. CVE-2026-15409 is a Server-Side Request Forgery (SSRF, CWE-918) vulnerability in the SMA1000 Appliance Work Place interface with CVSS 3.1 base score 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — the changed-scope (S:C) vector reflects the SSRF's ability to pivot the trust boundary from the appliance into internal or otherwise unreachable network segments, requiring no authentication and no user interaction. CVE-2026-15410 is a post-authentication Code Injection vulnerability (CWE-94, 'Improper Control of Generation of Code') in the SMA1000 Appliance Management Console (AMC), CVSS 3.1 base score 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), allowing an authenticated administrator-level attacker to execute arbitrary operating system commands on the underlying Linux platform. SonicWall assigned the advisory an overall severity of CVSS 10.0 reflecting the combined risk when the two bugs are chained.
SonicWall states it investigated multiple confirmed intrusion cases and, while it has not formally confirmed a single deterministic exploit chain, independent reporting (BleepingComputer, Help Net Security, The Hacker News) indicates the vulnerabilities are 'being exploited in tandem' in observed attacks: the unauthenticated SSRF is used for initial access/reconnaissance and to reach internal-only services, after which the authenticated code-injection flaw in the AMC is leveraged to obtain OS-level command execution on the appliance, granting the attacker durable control of the SMA1000 as an edge device and pivot point into the protected network.
Affected hardware/virtual models are SMA6210, SMA7210, and SMA8200v running vulnerable platform-hotfix builds: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall's SSL-VPN service on its firewalls and the separate SMA 100 Series product line are explicitly NOT affected. Patches are available as platform-hotfix 12.4.3-03453 (or later) and 12.5.0-02835 (or later) via the MySonicWall customer portal. SonicWall has published forensic IOC guidance (log entries in extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json) and states that patching alone is not sufficient — administrators must conduct forensic review for prior compromise and, if found, re-image physical appliances or redeploy virtual instances from a known-clean image, then reset all local user and administrator passwords and TOTP/MFA tokens, since credentials and secrets on a compromised appliance cannot be trusted.
CISA added both CVEs to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-14, with a Binding Operational Directive 26-04 remediation deadline of 2026-07-17 for Federal Civilian Executive Branch agencies — an unusually tight 3-day window reflecting the severity and confirmed in-the-wild exploitation. No public threat-actor attribution has been released as of publication; SonicWall and Volexity's investigation remains ongoing.
MITRE ATT&CK techniques used in TL-2026-1357
Collection
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Execution
T1059.004 Unix Shell; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Persistence
T1078 Valid Accounts; T1505.003 Web Shell
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Impact
T1498 Network Denial of Service
Credential Access
T1552.001 Credentials In Files; T1606 Forge Web Credentials
Resource Development
Reconnaissance
T1595.002 Vulnerability Scanning
defense-impairment
Affected products and versions in SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
- SonicWall — SMA1000 Series (SMA6210)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453 or later; 12.5.0-02835 or later - SonicWall — SMA1000 Series (SMA7210)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453 or later; 12.5.0-02835 or later - SonicWall — SMA1000 Series (SMA8200v)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453 or later; 12.5.0-02835 or later
Remediation for SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
Patches
- Platform-hotfix 12.4.3-03453 or later (12.4.3 branch)
- Platform-hotfix 12.5.0-02835 or later (12.5.0 branch)
Immediate actions
- Upgrade SMA1000 appliances to platform-hotfix 12.4.3-03453 or later, or 12.5.0-02835 or later, via MySonicWall
- Restrict WAN/internet access to the SMA1000 Work Place and Appliance Management Console interfaces where feasible
- Review extraweb_access.log for requests to /__api__/login or /__api__/logout returning HTTP 200
- Review extraweb_access.log for /wsproxy requests with anomalous host parameters returning HTTP 101
- Inspect ctrl-service.log for hotfix rollback entries containing path traversal sequences in the filename
- Inspect /var/lib/unit/conf.json for unauthorized routes referencing /__api__/login or /__api__/logout
Workarounds
- No effective workaround beyond patching is published by SonicWall; restrict interface exposure as a stopgap only
Longer-term hardening
- Segment management interfaces of edge/remote-access appliances from general internet exposure
- Deploy centralized log forwarding from SMA1000 appliances to a SIEM for retained forensic visibility
- Enforce MFA/TOTP on all SMA1000 administrator accounts and rotate on a defined schedule
- Establish a documented re-imaging/redeploy runbook for edge-appliance compromise response
- Subscribe to SonicWall PSIRT advisories and CISA KEV catalog updates for edge-device products in use
CVEs associated with SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
Weaknesses (CWE) in SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
CWE-918, CWE-94
Timeline of SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
- CISA publishes alert 'CISA Adds Four Known Exploited Vulnerabilities to Catalog,' including CVE-2026-15409 and CVE-2026-15410 among the additions, formally triggering Binding Operational Directive 26-04 remediation timelines for FCEB agencies.
- SonicWall credits PSIRT researcher Adam Babis for discovery/reporting of the two vulnerabilities and acknowledges Volexity co-founders Sean Koessel and Steven Adair for helping advance the internal investigation and identifying an additional indicator of compromise.
- SonicWall and Volexity (Sean Koessel, Steven Adair) publish forensic indicator-of-compromise guidance covering extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json artifacts.
- CISA adds CVE-2026-15409 and CVE-2026-15410 to the Known Exploited Vulnerabilities (KEV) catalog, triggering Binding Operational Directive 26-04.
- Patched platform-hotfix builds 12.4.3-03453 and 12.5.0-02835 made available to customers via MySonicWall.
- SonicWall PSIRT publishes advisory SNWLID-2026-0008 disclosing CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection, CVSS 7.2) in SMA1000 appliances, confirming active exploitation observed in customer investigations.
- Threat ingested into Threadlinqs Intelligence Platform via automated RSS hunt pipeline (TL-2026-1357).
- Cyber Security News, BleepingComputer, Help Net Security, and The Hacker News publish independent coverage reporting the two vulnerabilities are being exploited 'in tandem' in observed attacks.
- Deadline for U.S. Federal Civilian Executive Branch agencies to remediate under CISA Binding Operational Directive 26-04.
Sources cited for SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
- SonicWall Firewall 0-Day Vulnerabilities Exploited
- SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- SonicWall Security Advisory SNWLID-2026-0008
- NVD - CVE-2026-15409
- NVD - CVE-2026-15410
- CISA Known Exploited Vulnerabilities Catalog
- CVE-2026-15409 - Vulnerability-Lookup
- CVE-2026-15410 - Vulnerability-Lookup
- CISA Adds Four Known Exploited Vulnerabilities to Catalog
Threats related to SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
Detection coverage for TL-2026-1357
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1357 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.