CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE — Threadlinqs Intelligence
As of 2026-07-15, CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1385 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
SonicWall disclosed and patched two zero-day vulnerabilities in the SMA 1000 Series (models 6210, 7210, 8200v): CVE-2026-15409, a critical (CVSS 10.0) unauthenticated SSRF in the Workplace interface,
On July 14, 2026, SonicWall published Security Advisory SNWLID-2026-0008 disclosing two zero-day vulnerabilities in the SMA 1000 Series secure remote access appliances (models 6210, 7210, and 8200v, plus Central Management Server across all supported hypervisors) that SonicWall confirmed were being actively exploited in the wild prior to patch availability.
CVE-2026-15409 (CVSS 3.1: 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-918 Server-Side Request Forgery) resides in the SMA1000 Workplace interface and requires no authentication or user interaction. It allows a remote unauthenticated attacker to force the appliance to make network requests to unintended internal or external locations, effectively turning the appliance into an attacker-controlled proxy that can reach otherwise unreachable internal management surfaces. CVE-2026-15410 (CVSS 3.1: 7.2, high, CWE-94 Code Injection) is a post-authentication vulnerability in the Appliance Management Console (AMC) that permits a remote attacker holding administrator-level access to inject and execute arbitrary operating system commands.
SonicWall's investigation, aided by Volexity researchers Sean Koessel and Steven Adair (who identified an additional indicator of compromise), found that observed intrusions chain the two bugs: the unauthenticated SSRF in CVE-2026-15409 is leveraged to reach or interact with the administrative interface, after which the post-authentication code injection in CVE-2026-15410 is triggered to obtain arbitrary OS command execution as administrator. The combined chain therefore yields a fully remote, unauthenticated path to full appliance compromise without any legitimate credentials, despite CVE-2026-15410 nominally requiring authentication in isolation.
Vulnerable platform-hotfix releases span 12.4.3-03245, 12.4.3-03387, and 12.4.3-03434, and 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall shipped fixed hotfixes 12.4.3-03453 and 12.5.0-02835 (and later) with no interim workaround available for unpatched systems — CISA's Binding Operational Directive 26-04 required federal agencies to patch or disconnect affected appliances by July 17, 2026, just three days after public disclosure.
SonicWall published forensic indicators for organizations to hunt for prior compromise: anomalous HTTP 200 requests to `/__api__/login` and `/__api__/logout` in `extraweb_access.log`; suspicious `/wsproxy` requests carrying unusual `host` parameters returning HTTP 101 (WebSocket upgrade) responses, consistent with SSRF-driven proxying; hotfix-removal entries containing path-traversal-style names in `ctrl-service.log`, suggesting attacker tampering with patch/rollback mechanisms to persist access; and unauthorized routes injected into the `/var/lib/unit/conf.json` reverse-proxy configuration file, indicating attacker-added backend routes for persistent access or C2 relay through the compromised appliance. For any organization identifying these indicators, SonicWall's guidance is severe: re-image physical appliances or redeploy virtual instances from a known-clean image (using only backups predating the vulnerable hotfixes), reset all user and administrator credentials, and regenerate TOTP/MFA seeds — reflecting an assumption of full compromise rather than partial remediation.
SMA 1000 appliances are internet-facing secure remote access / SSL-VPN gateways broadly deployed across enterprise, government, financial, and healthcare environments to broker remote employee and third-party access into internal networks, making them a high-value initial-access target: successful exploitation grants a foothold inside the perimeter with a trusted vantage point for internal reconnaissance, credential harvesting, and lateral movement. SonicWall SMA/VPN appliances have a documented history as exploitation targets (e.g., CVE-2019-7481/7483, CVE-2021-20016/20038, CVE-2025-23006, CVE-2025-40602), including prior ransomware-affiliated exploitation of SMA/SSL-VPN devices, under
Weaknesses (CWE)
CWE-918, CWE-94
Target sectors: government administration, finance, health, technology, critical-infrastructure
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-15409, CVE-2026-15410, T1595, T1588, T1190, T1059, T1203, T1505, T1556, T1098, T1068, T1070