SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full (TL-2026-1396) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-16. It has no confirmed attribution, affects SonicWall SMA1000 Series (SMA6210, SMA7210, SMA8200v, CMS), references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 20 MITRE ATT&CK techniques (T1005, T1016, T1021.001), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1396
- Threat ID
- TL-2026-1396
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-16
- Last reviewed
- 2026-07-16
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all sectors using sonicwall sma1000 remote access, government administration, enterprise, critical infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
Attackers chained an unauthenticated critical SSRF (CVE-2026-15409, CVSS 10.0) in the SonicWall SMA1000 WorkPlace websocket proxy with a post-authentication OS command injection flaw (CVE-2026-15410, CVSS 7.2) in the Appliance Management Console to achieve full remote-code-execution compromise of SMA6210/7210/8200v appliances. Rapid7 MDR observed active in-the-wild exploitation from June 22, 2026, roughly three weeks before SonicWall's July 15, 2026 public disclosure; both CVEs were added to CISA KEV on July 14, 2026. Post-compromise activity harvested session/TOTP data and pivoted into on-premises Active Directory, with Rapid7 disrupting attempted data exfiltration and encryption consistent with a ransomware objective.
How SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full works
In June 2026 SonicWall's own PSIRT and third-party incident responders (Rapid7 MDR, Volexity) identified two zero-day vulnerabilities being actively exploited against SonicWall SMA1000-series Secure Mobile Access appliances (models SMA6210, SMA7210, SMA8200v, and the CMS management console) running hotfix firmware 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800.
The first vulnerability, CVE-2026-15409 (CVSS 3.1: 10.0, CWE-918 Server-Side Request Forgery), lives in the unauthenticated `/wsproxy` websocket-proxy endpoint of the SMA1000 WorkPlace web interface on TCP/443. By supplying attacker-controlled host and port parameters (e.g. `0.0.0.0`, `localhost`, `::ffff:127.0.0.1`, or loopback-mapped IPv4-in-IPv6 notation), a remote unauthenticated attacker forces the appliance to open a TCP tunnel to an internal-only service — most notably the `ctrl-service` administrative API listening on TCP/8188, which is normally reachable only from localhost.
Once tunneled into ctrl-service, the attacker abuses the second vulnerability, CVE-2026-15410 (CVSS 3.1: 7.2, CWE-94 Code Injection), a post-authentication OS command injection in the `remove_hotfix` workflow of the SMA1000 Appliance Management Console. The hotfix-name parameter is insufficiently sanitized, allowing path-traversal sequences (e.g. `../../../../tmp/malicious.sh`) that cause the appliance to execute an attacker-staged shell script as root during the (spoofed) hotfix-removal routine — effectively bypassing the intended administrator-authentication requirement because the SSRF tunnel presents the request as though it originated from localhost. The net effect, per VulnCheck exploit developer Landon Rice, is that "an attacker can go from zero access to a complete system compromise for the affected appliance."
Post-exploitation, observed intrusions harvested `/tmp/temp.db*` session-database files containing active session tokens and TOTP MFA seed material, then used the recovered material and the appliance's built-in LDAP service-account trust relationship to authenticate directly against on-premises Active Directory domain controllers without ever establishing a normal VPN session — producing anomalous Windows Event ID 4624 (logon type 3) logons sourced from the appliance's internal IP and non-inventory workstation names such as "kali". Rapid7 reported that in observed cases it disrupted attacker attempts at data exfiltration and file encryption, assessing the ultimate objective as ransomware deployment; overlapping tradecraft across incidents suggests a single actor or tightly coordinated group, though no named threat-actor or nation-state attribution has been publicly confirmed. Attacker source infrastructure was traced to IP ranges registered to FNS Holdings Limited (ASN 206092), a bulletproof/VPN-style hosting provider.
SonicWall released hotfixes 12.4.3-03453 and 12.5.0-02835 on July 15, 2026 (advisory SNWLID-2026-0008) with no interim workaround available; the company advises forensic review for indicators of compromise and, if found, full re-imaging of appliances and a complete credential/secret reset rather than trusting an in-place patch. CISA's Known Exploited Vulnerabilities catalog listing triggers Binding Operational Directive 26-04, requiring federal civilian agencies to remediate or discontinue use of affected appliances by July 17, 2026. Fewer than 5,000 SMA1000 units globally are estimated to be running the vulnerable configuration.
MITRE ATT&CK techniques used in TL-2026-1396
Collection
Discovery
T1016 System Network Configuration Discovery
Lateral Movement
T1021.001 Remote Desktop Protocol; T1210 Exploitation of Remote Services; T1550.001 Application Access Token
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
T1070 Indicator Removal; T1078 Valid Accounts; T1211 Exploitation for Stealth
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1572 Protocol Tunneling
Credential Access
T1111 Multi-Factor Authentication Interception; T1552.001 Credentials In Files; T1555 Credentials from Password Stores
Initial Access
T1190 Exploit Public-Facing Application
Impact
Affected products and versions in SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
- SonicWall — SMA1000 Series (SMA6210, SMA7210, SMA8200v, CMS)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453 and higher; 12.5.0-02835 and higher
Remediation for SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
Patches
- SonicWall firmware 12.4.3-03453 and higher
- SonicWall firmware 12.5.0-02835 and higher
Immediate actions
- Upgrade SMA1000 appliances to hotfix 12.4.3-03453 or 12.5.0-02835 or later immediately
- Restrict WorkPlace (443) and Appliance Management Console (8188) exposure to trusted management networks only
- Rotate all appliance-stored credentials, TOTP MFA seeds, and LDAP service-account secrets on any appliance suspected of compromise
- Terminate and invalidate all active session tokens tied to /tmp/temp.db* on affected appliances
Workarounds
- No interim workaround is available; SonicWall states patching is the only remediation
Longer-term hardening
- Conduct full forensic review and re-image any appliance showing IOCs rather than relying on in-place patching
- Segment SMA1000/VPN appliances from direct LDAP/AD trust relationships; require a jump/bastion layer for AD authentication
- Deploy EDR/monitoring on domain controllers to flag logons sourced from appliance internal IPs without a corresponding VPN session
- Audit non-inventory workstation names appearing in AD authentication logs
CVEs associated with SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
Weaknesses (CWE) in SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
CWE-918, CWE-94
Timeline of SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
- Threat actor begins an approximately three-week campaign exploiting the SSRF-to-code-injection chain across multiple SMA1000 customer environments prior to vendor disclosure.
- Rapid7 MDR observes the first confirmed in-the-wild exploitation of the CVE-2026-15409/CVE-2026-15410 chain against a SonicWall SMA1000 appliance.
- Rapid7 observes post-exploitation activity including harvesting of /tmp/temp.db* session and TOTP seed data and pivoting into on-premises Active Directory via the appliance's LDAP service account.
- Rapid7 disrupts attacker attempts at data exfiltration and file encryption on a victim network, assessing ransomware deployment as the likely objective.
- SonicWall publishes security advisory SNWLID-2026-0008 detailing both vulnerabilities and releases hotfixes 12.4.3-03453 and 12.5.0-02835.
- CISA adds CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities catalog, triggering Binding Operational Directive 26-04 remediation requirements for federal agencies.
- Public disclosure and mainstream security-press reporting (CyberScoop, BleepingComputer, The Hacker News, SecurityWeek) on the SMA1000 zero-day chain.
- Rapid7 publishes its emerging threat research blog detailing the exploit chain, post-exploitation TTPs, and indicators of compromise.
- Deadline for U.S. federal civilian executive branch agencies to remediate or discontinue use of affected SMA1000 appliances under BOD 26-04.
Sources cited for SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
- SonicWall customers under threat as attackers exploit 2 zero-days
- Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
- Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026-0008)
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
- SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
- NVD - CVE-2026-15409
- NVD - CVE-2026-15410
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-15409
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-15410
- CVE-2026-15409, CVE-2026-15410 Hit SonicWall SMA1000
Threats related to SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE
Detection coverage for TL-2026-1396
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1396 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.