SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited — Threadlinqs Intelligence
As of 2026-07-22, SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited is a critical-severity vulnerability threat attributed to UTA0533, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 44 indicators of compromise.
Threat ID: TL-2026-1382 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-22 · 4 updates · revalidated 4× · latest source
Attribution: UTA0533 · UNKNOWN
Rapid7 MDR and SonicWall confirmed active in-the-wild exploitation of two SMA1000 zero-days: an unauthenticated SSRF in the Workplace interface (CVE-2026-15409, CVSS 10.0) chained with a
On July 9, 2026, Rapid7's Managed Detection and Response (MDR) team observed active exploitation of two previously unknown vulnerabilities in SonicWall SMA1000 series secure remote access appliances (SMA6210, SMA7210, SMA8200v). SonicWall published a security advisory on July 14, 2026, and both flaws were added to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 15, 2026, triggering Binding Operational Directive (BOD) 26-04 with a federal remediation deadline of July 17, 2026.
The first flaw, CVE-2026-15409 (CVSS 3.1: 10.0, CWE-918 Server-Side Request Forgery), resides in the SMA1000 Appliance Work Place interface and is exploitable by a remote, unauthenticated attacker. The `/wsproxy` websocket-proxy endpoint accepts attacker-controlled `host` and `port` parameters intended for legitimate tunneling. By supplying localhost-bound addresses (0.0.0.0, 127.0.0.1, ::ffff:127.0.0.1), an attacker bypasses network segmentation and reaches internal-only services on the appliance itself, including an Erlang process listening on localhost:1050 that accepts a hardcoded, unauthenticated cookie value. This SSRF is used to reach and authenticate against internal management interfaces that are never meant to be internet-exposed, effectively granting the attacker an authenticated foothold without ever supplying real credentials.
The second flaw, CVE-2026-15410 (CVSS 3.1: 7.2, post-authentication Code Injection in the Appliance Management Console / AMC, reachable via ctrl-service on localhost:8188), allows a remote attacker who holds administrator-level access (obtained via the SSRF pivot or a stolen admin session) to execute arbitrary OS commands as root. The vulnerable code path is the `remove_hotfix` / hotfix-rollback workflow: the hotfix name parameter is insufficiently validated, allowing directory traversal sequences (e.g. `../../../../../tmp/malicious.sh`) that cause the appliance to execute an attacker-planted shell script via `/bin/bash` with root privileges from `/var/lib/aventail/avp/rollback/`, typically as part of a scripted reboot/rollback cycle.
Chained together, CVE-2026-15409 gives an unauthenticated attacker a path to an internal, effectively-authenticated context, and CVE-2026-15410 converts that context into unauthenticated-equivalent root remote code execution on the appliance — despite CVE-2026-15410 nominally requiring authentication. Rapid7 observed post-exploitation activity consistent with a credential-harvesting and lateral-movement playbook: attackers queried and exfiltrated data from appliance session/credential databases (including `/tmp/temp.db*`), harvested cached usernames/passwords and TOTP MFA seed values, and used the appliance's built-in LDAP service-account trust relationship to authenticate directly against the victim's Active Directory environment, generating NTLM logons (Windows Event ID 4624, logon type 3) sourced from the appliance's internal IP with non-standard workstation names (observed example: "kali") that had no corresponding VPN session — a strong host-based indicator that the appliance itself, not a VPN client, was authenticating.
No workarounds exist; SonicWall's guidance is that patching alone is not sufficient for previously-exploited appliances — affected organizations should assume compromise, review logs for the documented indicators, re-image affected appliances, reset all administrator and service-account passwords, and regenerate TOTP MFA seeds. Fixed platform-hotfix releases are 12.4.3-03453 and 12.5.0-02835. Rapid7 has released a Python proof-of-concept for the SSRF and has a Metasploit module in development; vulnerability checks are available in Rapid7 InsightVM, Nexpose, and Exposure Command. Volexity (Sean Koessel, Steven Adair) assisted SonicWall PSIRT (credited discoverer: Adam Babis) with investigation and IOC expansion. No specific threat-actor attribution has been publicly disclosed; targeting is opportunistic against internet-facing SMA1000 appliances acro
Weaknesses (CWE)
CWE-918, CWE-94, CWE-22, CWE-306, CWE-269, CWE-77
Target sectors: government administration, finance, health, technology, managedsecurityservices, criticalinfrastructure
Target regions: North America, Europe, Asia-Pacific, Global
Update History
- 2026-07-22 — Actively Exploited SonicWall SMA1000 Zero-Days — Unauthenticated SSRF + Admin Command Injection (CVE-2026-15409, CVE-2026-15410): What changed No field-level escalation: severity remains CRITICAL, exploitability remains ACTIVE, status remains ACTIVE, CVSS remains 10.0, attribution to UTA0533 remains LOW confidence. Added CWE-77 (Command Injection) alongside the existi
- 2026-07-19 — SonicWall SMA 1000 Series Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained by UTA0533 for Pre-Auth Root Compromise: What changed Actor attribution added: Unattributed → UTA0533 (Volexity). No change to severity/exploitability/status — both already CRITICAL/ACTIVE. New indicators (14) 14 new IOCs: ROOTRUN, KNUCKLEBALL, ORANGETAIL malware, the Suo5 tunneli
- 2026-07-19 — SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth RCE (CVE-2026-15410) Exploited in the Wild: What changed No field escalation — severity (CRITICAL), exploitability (ACTIVE), and status (ACTIVE) are unchanged and already at maximum. New indicators (3) 3 additional attacker-associated workstation-name IOCs (DESKTOP-KRLUI3J, DESKTOP-I
- 2026-07-16 — CVE-2026-15409 & CVE-2026-15410: Actively Exploited SonicWall SMA 1000 SSRF and Post-Auth Command Injection Chain: What changed No severity/exploitability/status escalation — both already CRITICAL/ACTIVE. Timeline revised: confirmed active exploitation now traced back to 2026-06-22 (true zero-day, ~3 weeks pre-disclosure) rather than the previously reco
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 44 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-15409, CVE-2026-15410, T1595, T1587.004, T1190, T1059.004, T1203, T1068, T1211, T1078, T1111, T1528