CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE

CVE-2026-15409 / CVE-2026-15410 (TL-2026-1385) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-15. It has no confirmed attribution, affects SonicWall SMA 1000 Series (SMA6210, SMA7210, SMA8200v, Central, references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 19 MITRE ATT&CK techniques (T1016, T1046, T1059), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1385

Threat ID
TL-2026-1385
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-15
Last reviewed
2026-07-15
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, critical-infrastructure
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
20

SonicWall disclosed and patched two zero-day vulnerabilities in the SMA 1000 Series (models 6210, 7210, 8200v): CVE-2026-15409, a critical (CVSS 10.0) unauthenticated SSRF in the Workplace interface, and CVE-2026-15410, a high-severity (CVSS 7.2) post-authentication code injection in the Appliance Management Console. Threat actors are actively chaining the two flaws to achieve fully remote, unauthenticated arbitrary OS command execution; both CVEs were added to the CISA KEV catalog with a July 17, 2026 federal remediation deadline.

How CVE-2026-15409 / CVE-2026-15410 works

On July 14, 2026, SonicWall published Security Advisory SNWLID-2026-0008 disclosing two zero-day vulnerabilities in the SMA 1000 Series secure remote access appliances (models 6210, 7210, and 8200v, plus Central Management Server across all supported hypervisors) that SonicWall confirmed were being actively exploited in the wild prior to patch availability.

CVE-2026-15409 (CVSS 3.1: 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-918 Server-Side Request Forgery) resides in the SMA1000 Workplace interface and requires no authentication or user interaction. It allows a remote unauthenticated attacker to force the appliance to make network requests to unintended internal or external locations, effectively turning the appliance into an attacker-controlled proxy that can reach otherwise unreachable internal management surfaces. CVE-2026-15410 (CVSS 3.1: 7.2, high, CWE-94 Code Injection) is a post-authentication vulnerability in the Appliance Management Console (AMC) that permits a remote attacker holding administrator-level access to inject and execute arbitrary operating system commands.

SonicWall's investigation, aided by Volexity researchers Sean Koessel and Steven Adair (who identified an additional indicator of compromise), found that observed intrusions chain the two bugs: the unauthenticated SSRF in CVE-2026-15409 is leveraged to reach or interact with the administrative interface, after which the post-authentication code injection in CVE-2026-15410 is triggered to obtain arbitrary OS command execution as administrator. The combined chain therefore yields a fully remote, unauthenticated path to full appliance compromise without any legitimate credentials, despite CVE-2026-15410 nominally requiring authentication in isolation.

Vulnerable platform-hotfix releases span 12.4.3-03245, 12.4.3-03387, and 12.4.3-03434, and 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall shipped fixed hotfixes 12.4.3-03453 and 12.5.0-02835 (and later) with no interim workaround available for unpatched systems — CISA's Binding Operational Directive 26-04 required federal agencies to patch or disconnect affected appliances by July 17, 2026, just three days after public disclosure.

SonicWall published forensic indicators for organizations to hunt for prior compromise: anomalous HTTP 200 requests to `/__api__/login` and `/__api__/logout` in `extraweb_access.log`; suspicious `/wsproxy` requests carrying unusual `host` parameters returning HTTP 101 (WebSocket upgrade) responses, consistent with SSRF-driven proxying; hotfix-removal entries containing path-traversal-style names in `ctrl-service.log`, suggesting attacker tampering with patch/rollback mechanisms to persist access; and unauthorized routes injected into the `/var/lib/unit/conf.json` reverse-proxy configuration file, indicating attacker-added backend routes for persistent access or C2 relay through the compromised appliance. For any organization identifying these indicators, SonicWall's guidance is severe: re-image physical appliances or redeploy virtual instances from a known-clean image (using only backups predating the vulnerable hotfixes), reset all user and administrator credentials, and regenerate TOTP/MFA seeds — reflecting an assumption of full compromise rather than partial remediation.

SMA 1000 appliances are internet-facing secure remote access / SSL-VPN gateways broadly deployed across enterprise, government, financial, and healthcare environments to broker remote employee and third-party access into internal networks, making them a high-value initial-access target: successful exploitation grants a foothold inside the perimeter with a trusted vantage point for internal reconnaissance, credential harvesting, and lateral movement. SonicWall SMA/VPN appliances have a documented history as exploitation targets (e.g., CVE-2019-7481/7483, CVE-2021-20016/20038, CVE-2025-23006, CVE-2025-40602), including prior ransomware-affiliated exploitation of SMA/SSL-VPN devices, underscoring the recurring pattern of edge-appliance zero-days being weaponized rapidly by opportunistic and targeted threat actors alike. No specific threat actor group has been publicly attributed to this campaign as of this writing; SonicWall and Volexity have not disclosed network-layer IOCs (IPs, domains, hashes) publicly, limiting available detection to the host/log-based forensic artifacts above.

MITRE ATT&CK techniques used in TL-2026-1385

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Defense Evasion

T1070 Indicator Removal; T1211 Exploitation for Stealth

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Persistence

T1098 Account Manipulation; T1505 Server Software Component; T1556 Modify Authentication Process

Credential Access

T1111 Multi-Factor Authentication Interception; T1552 Unsecured Credentials

Initial Access

T1190 Exploit Public-Facing Application

initial-access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

defense-impairment

T1601 Modify System Image

Affected products and versions in CVE-2026-15409 / CVE-2026-15410

  • SonicWall — SMA 1000 Series (SMA6210, SMA7210, SMA8200v, Central Management Server - all hypervisors)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453 and later; 12.5.0-02835 and later

Remediation for CVE-2026-15409 / CVE-2026-15410

Patches

  • SonicWall platform-hotfix 12.4.3-03453 or later (fixes versions 12.4.3-03245, 12.4.3-03387, 12.4.3-03434)
  • SonicWall platform-hotfix 12.5.0-02835 or later (fixes versions 12.5.0-02283, 12.5.0-02624, 12.5.0-02800)

Immediate actions

  • Upgrade all SMA 1000 Series appliances (6210, 7210, 8200v) and CMS instances to platform-hotfix 12.4.3-03453 or later, or 12.5.0-02835 or later, via mysonicwall.com
  • Review extraweb_access.log for anomalous HTTP 200 requests to /__api__/login and /__api__/logout
  • Review access/proxy logs for suspicious /wsproxy requests with anomalous host parameters returning HTTP 101
  • Review ctrl-service.log for hotfix-removal entries containing path-traversal-style names
  • Inspect /var/lib/unit/conf.json for unauthorized/unexpected routes
  • Comply with CISA Binding Operational Directive 26-04: remediate or disconnect affected appliances by 2026-07-17

Workarounds

  • No interim workaround is available; SonicWall states patching is the only mitigation
  • Organizations unable to patch immediately should disconnect/discontinue use of the affected SMA1000 appliance per CISA BOD 26-04 guidance

Longer-term hardening

  • If any compromise indicator is found, re-image physical appliances or redeploy virtual SMA1000 instances from a known-clean image predating the vulnerable hotfixes
  • Reset all user and administrator credentials on affected appliances
  • Regenerate/reset all TOTP/MFA seeds tied to the appliance
  • Restrict management-plane (AMC) exposure to trusted management networks only, not the general internet
  • Deploy network monitoring/IDS rules for anomalous SSRF-style outbound requests originating from SMA1000 appliances
  • Establish a rapid-patch SLA for internet-facing SSL-VPN/remote-access appliances given the recurring history of SonicWall SMA zero-days

CVEs associated with CVE-2026-15409 / CVE-2026-15410

CVE-2026-15409, CVE-2026-15410

Weaknesses (CWE) in CVE-2026-15409 / CVE-2026-15410

CWE-918, CWE-94

Timeline of CVE-2026-15409 / CVE-2026-15410

  • Patched platform-hotfix releases 12.4.3-03453 and 12.5.0-02835 become available via mysonicwall.com.
  • Help Net Security, SecurityWeek, and other outlets publish initial coverage of the active zero-day exploitation.
  • SonicWall credits Volexity researchers Sean Koessel and Steven Adair with assisting the PSIRT investigation and identifying an additional indicator of compromise.
  • CISA adds both CVE-2026-15409 and CVE-2026-15410 to the Known Exploited Vulnerabilities (KEV) catalog, invoking Binding Operational Directive 26-04.
  • SonicWall publishes Security Advisory SNWLID-2026-0008 disclosing CVE-2026-15409 and CVE-2026-15410 in SMA 1000 Series appliances, confirming active exploitation and releasing patched hotfixes.
  • The Hacker News publishes coverage detailing the SSRF-to-code-injection chaining and IOC guidance for compromise hunting.
  • Tenable publishes technical blog analysis of CVE-2026-15409 and CVE-2026-15410, the source article that triggered this hunt.
  • CISA Binding Operational Directive 26-04 remediation deadline: US federal agencies must patch or disconnect affected SMA 1000 appliances.

Sources cited for CVE-2026-15409 / CVE-2026-15410

Threats related to CVE-2026-15409 / CVE-2026-15410

Detection coverage for TL-2026-1385

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1385 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats