SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem

SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409 (TL-2026-1357), also tracked as SNWLID-2026-0008, is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-15. It has no confirmed attribution, affects SonicWall SMA1000 Series (SMA6210), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 18 MITRE ATT&CK techniques (T1005, T1046, T1059.004), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1357

Threat ID
TL-2026-1357
Also known as
SNWLID-2026-0008
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-15
Last reviewed
2026-07-15
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, critical-infrastructure, education, retail
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
18

SonicWall PSIRT confirmed active, in-the-wild exploitation of two SMA1000 Series zero-days: an unauthenticated SSRF in the Workplace interface (CVE-2026-15409, CVSS 10.0) and a post-authentication OS command injection in the Appliance Management Console (CVE-2026-15410, CVSS 7.2). Attackers have been observed chaining the two flaws together against SMA6210, SMA7210, and SMA8200v appliances running platform-hotfix 12.4.3 or 12.5.0. Volexity assisted SonicWall's investigation and IOC development.

How SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409 works

On 2026-07-14, SonicWall PSIRT published advisory SNWLID-2026-0008 disclosing two zero-day vulnerabilities in the SMA1000 Series Secure Mobile Access appliance line that are being actively exploited against customer environments. CVE-2026-15409 is a Server-Side Request Forgery (SSRF, CWE-918) vulnerability in the SMA1000 Appliance Work Place interface with CVSS 3.1 base score 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — the changed-scope (S:C) vector reflects the SSRF's ability to pivot the trust boundary from the appliance into internal or otherwise unreachable network segments, requiring no authentication and no user interaction. CVE-2026-15410 is a post-authentication Code Injection vulnerability (CWE-94, 'Improper Control of Generation of Code') in the SMA1000 Appliance Management Console (AMC), CVSS 3.1 base score 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), allowing an authenticated administrator-level attacker to execute arbitrary operating system commands on the underlying Linux platform. SonicWall assigned the advisory an overall severity of CVSS 10.0 reflecting the combined risk when the two bugs are chained.

SonicWall states it investigated multiple confirmed intrusion cases and, while it has not formally confirmed a single deterministic exploit chain, independent reporting (BleepingComputer, Help Net Security, The Hacker News) indicates the vulnerabilities are 'being exploited in tandem' in observed attacks: the unauthenticated SSRF is used for initial access/reconnaissance and to reach internal-only services, after which the authenticated code-injection flaw in the AMC is leveraged to obtain OS-level command execution on the appliance, granting the attacker durable control of the SMA1000 as an edge device and pivot point into the protected network.

Affected hardware/virtual models are SMA6210, SMA7210, and SMA8200v running vulnerable platform-hotfix builds: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall's SSL-VPN service on its firewalls and the separate SMA 100 Series product line are explicitly NOT affected. Patches are available as platform-hotfix 12.4.3-03453 (or later) and 12.5.0-02835 (or later) via the MySonicWall customer portal. SonicWall has published forensic IOC guidance (log entries in extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json) and states that patching alone is not sufficient — administrators must conduct forensic review for prior compromise and, if found, re-image physical appliances or redeploy virtual instances from a known-clean image, then reset all local user and administrator passwords and TOTP/MFA tokens, since credentials and secrets on a compromised appliance cannot be trusted.

CISA added both CVEs to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-14, with a Binding Operational Directive 26-04 remediation deadline of 2026-07-17 for Federal Civilian Executive Branch agencies — an unusually tight 3-day window reflecting the severity and confirmed in-the-wild exploitation. No public threat-actor attribution has been released as of publication; SonicWall and Volexity's investigation remains ongoing.

MITRE ATT&CK techniques used in TL-2026-1357

Collection

T1005 Data from Local System

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Execution

T1059.004 Unix Shell; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Persistence

T1078 Valid Accounts; T1505.003 Web Shell

Command and Control

T1090.001 Internal Proxy

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1498 Network Denial of Service

Credential Access

T1552.001 Credentials In Files; T1606 Forge Web Credentials

Resource Development

T1588.005 Exploits

Reconnaissance

T1595.002 Vulnerability Scanning

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

  • SonicWall — SMA1000 Series (SMA6210)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453 or later; 12.5.0-02835 or later
  • SonicWall — SMA1000 Series (SMA7210)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453 or later; 12.5.0-02835 or later
  • SonicWall — SMA1000 Series (SMA8200v)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453 or later; 12.5.0-02835 or later

Remediation for SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

Patches

  • Platform-hotfix 12.4.3-03453 or later (12.4.3 branch)
  • Platform-hotfix 12.5.0-02835 or later (12.5.0 branch)

Immediate actions

  • Upgrade SMA1000 appliances to platform-hotfix 12.4.3-03453 or later, or 12.5.0-02835 or later, via MySonicWall
  • Restrict WAN/internet access to the SMA1000 Work Place and Appliance Management Console interfaces where feasible
  • Review extraweb_access.log for requests to /__api__/login or /__api__/logout returning HTTP 200
  • Review extraweb_access.log for /wsproxy requests with anomalous host parameters returning HTTP 101
  • Inspect ctrl-service.log for hotfix rollback entries containing path traversal sequences in the filename
  • Inspect /var/lib/unit/conf.json for unauthorized routes referencing /__api__/login or /__api__/logout

Workarounds

  • No effective workaround beyond patching is published by SonicWall; restrict interface exposure as a stopgap only

Longer-term hardening

  • Segment management interfaces of edge/remote-access appliances from general internet exposure
  • Deploy centralized log forwarding from SMA1000 appliances to a SIEM for retained forensic visibility
  • Enforce MFA/TOTP on all SMA1000 administrator accounts and rotate on a defined schedule
  • Establish a documented re-imaging/redeploy runbook for edge-appliance compromise response
  • Subscribe to SonicWall PSIRT advisories and CISA KEV catalog updates for edge-device products in use

CVEs associated with SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

CVE-2026-15409, CVE-2026-15410

Weaknesses (CWE) in SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

CWE-918, CWE-94

Timeline of SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

  • CISA publishes alert 'CISA Adds Four Known Exploited Vulnerabilities to Catalog,' including CVE-2026-15409 and CVE-2026-15410 among the additions, formally triggering Binding Operational Directive 26-04 remediation timelines for FCEB agencies.
  • SonicWall credits PSIRT researcher Adam Babis for discovery/reporting of the two vulnerabilities and acknowledges Volexity co-founders Sean Koessel and Steven Adair for helping advance the internal investigation and identifying an additional indicator of compromise.
  • SonicWall and Volexity (Sean Koessel, Steven Adair) publish forensic indicator-of-compromise guidance covering extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json artifacts.
  • CISA adds CVE-2026-15409 and CVE-2026-15410 to the Known Exploited Vulnerabilities (KEV) catalog, triggering Binding Operational Directive 26-04.
  • Patched platform-hotfix builds 12.4.3-03453 and 12.5.0-02835 made available to customers via MySonicWall.
  • SonicWall PSIRT publishes advisory SNWLID-2026-0008 disclosing CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection, CVSS 7.2) in SMA1000 appliances, confirming active exploitation observed in customer investigations.
  • Threat ingested into Threadlinqs Intelligence Platform via automated RSS hunt pipeline (TL-2026-1357).
  • Cyber Security News, BleepingComputer, Help Net Security, and The Hacker News publish independent coverage reporting the two vulnerabilities are being exploited 'in tandem' in observed attacks.
  • Deadline for U.S. Federal Civilian Executive Branch agencies to remediate under CISA Binding Operational Directive 26-04.

Sources cited for SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

Threats related to SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409

Detection coverage for TL-2026-1357

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1357 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats