CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE
CVE-2026-15409 / CVE-2026-15410 (TL-2026-1385) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-15. It has no confirmed attribution, affects SonicWall SMA 1000 Series (SMA6210, SMA7210, SMA8200v, Central, references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 19 MITRE ATT&CK techniques (T1016, T1046, T1059), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1385
- Threat ID
- TL-2026-1385
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, critical-infrastructure
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 20
SonicWall disclosed and patched two zero-day vulnerabilities in the SMA 1000 Series (models 6210, 7210, 8200v): CVE-2026-15409, a critical (CVSS 10.0) unauthenticated SSRF in the Workplace interface, and CVE-2026-15410, a high-severity (CVSS 7.2) post-authentication code injection in the Appliance Management Console. Threat actors are actively chaining the two flaws to achieve fully remote, unauthenticated arbitrary OS command execution; both CVEs were added to the CISA KEV catalog with a July 17, 2026 federal remediation deadline.
How CVE-2026-15409 / CVE-2026-15410 works
On July 14, 2026, SonicWall published Security Advisory SNWLID-2026-0008 disclosing two zero-day vulnerabilities in the SMA 1000 Series secure remote access appliances (models 6210, 7210, and 8200v, plus Central Management Server across all supported hypervisors) that SonicWall confirmed were being actively exploited in the wild prior to patch availability.
CVE-2026-15409 (CVSS 3.1: 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-918 Server-Side Request Forgery) resides in the SMA1000 Workplace interface and requires no authentication or user interaction. It allows a remote unauthenticated attacker to force the appliance to make network requests to unintended internal or external locations, effectively turning the appliance into an attacker-controlled proxy that can reach otherwise unreachable internal management surfaces. CVE-2026-15410 (CVSS 3.1: 7.2, high, CWE-94 Code Injection) is a post-authentication vulnerability in the Appliance Management Console (AMC) that permits a remote attacker holding administrator-level access to inject and execute arbitrary operating system commands.
SonicWall's investigation, aided by Volexity researchers Sean Koessel and Steven Adair (who identified an additional indicator of compromise), found that observed intrusions chain the two bugs: the unauthenticated SSRF in CVE-2026-15409 is leveraged to reach or interact with the administrative interface, after which the post-authentication code injection in CVE-2026-15410 is triggered to obtain arbitrary OS command execution as administrator. The combined chain therefore yields a fully remote, unauthenticated path to full appliance compromise without any legitimate credentials, despite CVE-2026-15410 nominally requiring authentication in isolation.
Vulnerable platform-hotfix releases span 12.4.3-03245, 12.4.3-03387, and 12.4.3-03434, and 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall shipped fixed hotfixes 12.4.3-03453 and 12.5.0-02835 (and later) with no interim workaround available for unpatched systems — CISA's Binding Operational Directive 26-04 required federal agencies to patch or disconnect affected appliances by July 17, 2026, just three days after public disclosure.
SonicWall published forensic indicators for organizations to hunt for prior compromise: anomalous HTTP 200 requests to `/__api__/login` and `/__api__/logout` in `extraweb_access.log`; suspicious `/wsproxy` requests carrying unusual `host` parameters returning HTTP 101 (WebSocket upgrade) responses, consistent with SSRF-driven proxying; hotfix-removal entries containing path-traversal-style names in `ctrl-service.log`, suggesting attacker tampering with patch/rollback mechanisms to persist access; and unauthorized routes injected into the `/var/lib/unit/conf.json` reverse-proxy configuration file, indicating attacker-added backend routes for persistent access or C2 relay through the compromised appliance. For any organization identifying these indicators, SonicWall's guidance is severe: re-image physical appliances or redeploy virtual instances from a known-clean image (using only backups predating the vulnerable hotfixes), reset all user and administrator credentials, and regenerate TOTP/MFA seeds — reflecting an assumption of full compromise rather than partial remediation.
SMA 1000 appliances are internet-facing secure remote access / SSL-VPN gateways broadly deployed across enterprise, government, financial, and healthcare environments to broker remote employee and third-party access into internal networks, making them a high-value initial-access target: successful exploitation grants a foothold inside the perimeter with a trusted vantage point for internal reconnaissance, credential harvesting, and lateral movement. SonicWall SMA/VPN appliances have a documented history as exploitation targets (e.g., CVE-2019-7481/7483, CVE-2021-20016/20038, CVE-2025-23006, CVE-2025-40602), including prior ransomware-affiliated exploitation of SMA/SSL-VPN devices, underscoring the recurring pattern of edge-appliance zero-days being weaponized rapidly by opportunistic and targeted threat actors alike. No specific threat actor group has been publicly attributed to this campaign as of this writing; SonicWall and Volexity have not disclosed network-layer IOCs (IPs, domains, hashes) publicly, limiting available detection to the host/log-based forensic artifacts above.
MITRE ATT&CK techniques used in TL-2026-1385
Discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
T1070 Indicator Removal; T1211 Exploitation for Stealth
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Persistence
T1098 Account Manipulation; T1505 Server Software Component; T1556 Modify Authentication Process
Credential Access
T1111 Multi-Factor Authentication Interception; T1552 Unsecured Credentials
Initial Access
T1190 Exploit Public-Facing Application
initial-access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Resource Development
Reconnaissance
defense-impairment
Affected products and versions in CVE-2026-15409 / CVE-2026-15410
- SonicWall — SMA 1000 Series (SMA6210, SMA7210, SMA8200v, Central Management Server - all hypervisors)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453 and later; 12.5.0-02835 and later
Remediation for CVE-2026-15409 / CVE-2026-15410
Patches
- SonicWall platform-hotfix 12.4.3-03453 or later (fixes versions 12.4.3-03245, 12.4.3-03387, 12.4.3-03434)
- SonicWall platform-hotfix 12.5.0-02835 or later (fixes versions 12.5.0-02283, 12.5.0-02624, 12.5.0-02800)
Immediate actions
- Upgrade all SMA 1000 Series appliances (6210, 7210, 8200v) and CMS instances to platform-hotfix 12.4.3-03453 or later, or 12.5.0-02835 or later, via mysonicwall.com
- Review extraweb_access.log for anomalous HTTP 200 requests to /__api__/login and /__api__/logout
- Review access/proxy logs for suspicious /wsproxy requests with anomalous host parameters returning HTTP 101
- Review ctrl-service.log for hotfix-removal entries containing path-traversal-style names
- Inspect /var/lib/unit/conf.json for unauthorized/unexpected routes
- Comply with CISA Binding Operational Directive 26-04: remediate or disconnect affected appliances by 2026-07-17
Workarounds
- No interim workaround is available; SonicWall states patching is the only mitigation
- Organizations unable to patch immediately should disconnect/discontinue use of the affected SMA1000 appliance per CISA BOD 26-04 guidance
Longer-term hardening
- If any compromise indicator is found, re-image physical appliances or redeploy virtual SMA1000 instances from a known-clean image predating the vulnerable hotfixes
- Reset all user and administrator credentials on affected appliances
- Regenerate/reset all TOTP/MFA seeds tied to the appliance
- Restrict management-plane (AMC) exposure to trusted management networks only, not the general internet
- Deploy network monitoring/IDS rules for anomalous SSRF-style outbound requests originating from SMA1000 appliances
- Establish a rapid-patch SLA for internet-facing SSL-VPN/remote-access appliances given the recurring history of SonicWall SMA zero-days
CVEs associated with CVE-2026-15409 / CVE-2026-15410
Weaknesses (CWE) in CVE-2026-15409 / CVE-2026-15410
CWE-918, CWE-94
Timeline of CVE-2026-15409 / CVE-2026-15410
- Patched platform-hotfix releases 12.4.3-03453 and 12.5.0-02835 become available via mysonicwall.com.
- Help Net Security, SecurityWeek, and other outlets publish initial coverage of the active zero-day exploitation.
- SonicWall credits Volexity researchers Sean Koessel and Steven Adair with assisting the PSIRT investigation and identifying an additional indicator of compromise.
- CISA adds both CVE-2026-15409 and CVE-2026-15410 to the Known Exploited Vulnerabilities (KEV) catalog, invoking Binding Operational Directive 26-04.
- SonicWall publishes Security Advisory SNWLID-2026-0008 disclosing CVE-2026-15409 and CVE-2026-15410 in SMA 1000 Series appliances, confirming active exploitation and releasing patched hotfixes.
- The Hacker News publishes coverage detailing the SSRF-to-code-injection chaining and IOC guidance for compromise hunting.
- Tenable publishes technical blog analysis of CVE-2026-15409 and CVE-2026-15410, the source article that triggered this hunt.
- CISA Binding Operational Directive 26-04 remediation deadline: US federal agencies must patch or disconnect affected SMA 1000 appliances.
Sources cited for CVE-2026-15409 / CVE-2026-15410
- Tenable: CVE-2026-15409 & CVE-2026-15410 SonicWall SMA 1000 Zero-Day Vulnerabilities Exploited in the Wild
- SonicWall Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- BleepingComputer: SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
- The Hacker News: Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- Help Net Security: SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
- Halo Security: CVE-2026-15409 SonicWall SMA1000 SSRF Vulnerability Advisory
- SecurityWeek: SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
Threats related to CVE-2026-15409 / CVE-2026-15410
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in Tandem
Detection coverage for TL-2026-1385
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1385 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.