Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)

Actively Exploited SonicWall SMA1000 Zero-Days (TL-2026-1451) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-17. It has no confirmed attribution, affects SonicWall SMA1000 (Secure Mobile Access), references 5 CVEs (CVE-2026-15409, CVE-2026-15410, CVE-2026-56164), maps to 23 MITRE ATT&CK techniques (T1005, T1021, T1021.004), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1451

Threat ID
TL-2026-1451
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-17
Last reviewed
2026-07-17
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, critical-infrastructure, professional-services
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
27

SonicWall disclosed and patched two actively exploited SMA1000 zero-days — a pre-auth CVSS 10.0 SSRF (CVE-2026-15409) chained with a post-auth path-traversal code injection (CVE-2026-15410) — that attackers used to gain root on internet-facing appliances, harvest credentials/TOTP seeds, and pivot into Active Directory. Concurrently, Microsoft's record-breaking July 2026 Patch Tuesday fixed 570 vulnerabilities including two actively exploited zero-days (SharePoint Server CVE-2026-56164, AD FS CVE-2026-56155) and one publicly disclosed BitLocker bypass (CVE-2026-50661), a volume Microsoft attributes to its new AI-powered vulnerability-discovery tooling.

How Actively Exploited SonicWall SMA1000 Zero-Days works

This threat bundles two concurrent, high-severity vendor patch events from mid-July 2026 that both demand urgent perimeter and identity-infrastructure remediation.

SonicWall SMA1000: Rapid7 MDR observed active, targeted exploitation of internet-facing SMA1000-series appliances (models 6210, 7210, 8200v) beginning as early as late June 2026, with confirmed exploitation activity from July 9, 2026. Attackers chain two flaws. CVE-2026-15409 (CVSS 10.0) is a server-side request forgery in the WorkPlace websocket proxy feature (/wsproxy, port 443) that lets an unauthenticated remote attacker supply a localhost-pointing host value, causing the appliance to reach less-hardened internal-only services — notably an Erlang process listening on localhost:1050 — without any credentials. Once that internal foothold is established, CVE-2026-15410 is a post-authentication path-traversal / code-injection vulnerability in the remove_hotfix workflow of the ctrl-service (port 8188, Appliance Management Console); supplying a malicious hotfix path containing directory-traversal sequences (e.g. ../../../../../../tmp/payload.sh) causes the AMC to execute the attacker's script as root. SonicWall confirmed there is no workaround — only patching remediates. Post-compromise, threat actors harvested high-value credentials, active VPN session databases, and TOTP MFA seed configurations from the appliance, then used those credentials to move laterally, including anomalous VPN-less Active Directory authentications against core domain controllers originating from the appliance's internal IP address — effectively using the SMA1000 as an undetected backdoor into the internal AD environment. CISA added both CVEs to the KEV catalog with a July 17, 2026 FCEB remediation deadline. Patched versions: 12.4.3-03453 (platform-hotfix) or later, and 12.5.0-02835 (platform-hotfix) or later.

Microsoft July 2026 Patch Tuesday: Microsoft shipped fixes for a record 570 vulnerabilities (breakdown: 254 Elevation of Privilege, 145 Remote Code Execution, 102 Information Disclosure, 35 Denial of Service, 17 Security Feature Bypass, 16 Spoofing; 59 rated Critical, 48 of those RCE). Microsoft attributed the unprecedented volume in part to a newly deployed AI-powered vulnerability-discovery system scanning the Windows codebase proactively. Three zero-days were addressed: CVE-2026-56164, an unauthenticated elevation-of-privilege in SharePoint Server (2016, 2019, Subscription Edition) caused by a missing authentication check (CWE-306) in the User Profiles assembly that lets an unauthenticated network attacker escalate to Farm Administrator by omitting the security digest and supplying crafted routing headers — discovered by Mandiant/Google FLARE during real-world incident response and actively exploited despite a deceptively low CVSS of 5.3; CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS) rooted in insufficiently granular Distributed Key Management (DKM) container ACLs that lets a low-privileged authenticated local attacker reach administrator level and potentially expose the private keys backing an organization's federation tokens, with functional exploit code observed in the wild (CVSS 7.8); and CVE-2026-50661, a publicly disclosed (not yet observed exploited) BitLocker security-feature-bypass. Both CVE-2026-56164 and CVE-2026-56155 were added to CISA KEV. Interim mitigation for the SharePoint flaw includes enabling AMSI integration with Full Request Body Scan mode pending patch deployment on internet-facing farms.

Together, these events represent a coordinated pressure point on perimeter VPN/SSL-VPN appliances and core identity infrastructure (AD FS, SharePoint) in the same week, raising the likelihood of opportunistic and targeted follow-on exploitation by multiple threat clusters before organizations complete patching.

MITRE ATT&CK techniques used in TL-2026-1451

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services; T1021.004 SSH; T1550 Use Alternate Authentication Material

Discovery

T1046 Network Service Discovery; T1087.002 Domain Account

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Persistence

T1078 Valid Accounts; T1505 Server Software Component

discovery

T1083 File and Directory Discovery

Command and Control

T1090 Proxy; T1090.001 Internal Proxy

Credential Access

T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1558 Steal or Forge Kerberos Tickets

Initial Access

T1190 Exploit Public-Facing Application

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1531 Account Access Removal

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Actively Exploited SonicWall SMA1000 Zero-Days

  • SonicWall — SMA1000 (Secure Mobile Access)
    Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
    Fixed in: 12.4.3-03453 (platform-hotfix) or later; 12.5.0-02835 (platform-hotfix) or later
  • SonicWall — SMA 1000 Series appliance models
    Vulnerable versions: 6210; 7210; 8200v
  • Microsoft — SharePoint Server
    Vulnerable versions: SharePoint Server 2016; SharePoint Server 2019; SharePoint Server Subscription Edition
    Fixed in: July 14, 2026 cumulative security update
  • Microsoft — Windows Server (Active Directory Federation Services)
    Vulnerable versions: Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022; Windows Server 2025
    Fixed in: July 14, 2026 security update
  • Microsoft — Windows (BitLocker)
    Vulnerable versions: Windows versions supporting BitLocker prior to July 2026 update
    Fixed in: July 14, 2026 security update

Remediation for Actively Exploited SonicWall SMA1000 Zero-Days

Patches

  • SonicWall SMA1000 12.4.3-03453 (platform-hotfix) or later
  • SonicWall SMA1000 12.5.0-02835 (platform-hotfix) or later
  • Microsoft July 2026 Patch Tuesday cumulative update (KB covering CVE-2026-56164, CVE-2026-56155, CVE-2026-50661)
  • Microsoft KB5121391 (AD FS DKM container ACL hardening for CVE-2026-56155)

Immediate actions

  • Patch SonicWall SMA1000 appliances to 12.4.3-03453 (platform-hotfix) or later, or 12.5.0-02835 (platform-hotfix) or later
  • Patch Microsoft SharePoint Server (2016, 2019, Subscription Edition) with the July 14, 2026 security update addressing CVE-2026-56164
  • Apply the July 14, 2026 Windows Server security update addressing CVE-2026-56155 (AD FS) across Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025
  • Perform forensic analysis of internet-facing SMA1000 appliances for signs of prior compromise before/after patching
  • Rotate all credentials, VPN session tokens, and TOTP MFA seeds stored on or accessible via SMA1000 appliances that were internet-facing prior to patching
  • Review Active Directory authentication logs for anomalous VPN-less logons to domain controllers originating from SMA1000 appliance internal IPs (Event ID 4624, logon type 3)

Workarounds

  • None available for SonicWall SMA1000 flaws — SonicWall confirmed no workaround exists
  • Enable AMSI integration with Full Request Body Scan mode as interim mitigation for CVE-2026-56164 on internet-facing SharePoint farms pending patch

Longer-term hardening

  • Harden AD FS Distributed Key Management (DKM) container ACLs per Microsoft KB5121391 guidance ahead of the October enforcement deadline
  • Deploy EDR/NDR with behavioral detection on appliance management interfaces and identity infrastructure
  • Segment SSL-VPN/SMA appliance management interfaces from direct internet exposure
  • Establish routine patch cadence tracking for CISA KEV additions affecting perimeter and identity systems

CVEs associated with Actively Exploited SonicWall SMA1000 Zero-Days

CVE-2026-15409, CVE-2026-15410, CVE-2026-56164, CVE-2026-56155, CVE-2026-50661

Weaknesses (CWE) in Actively Exploited SonicWall SMA1000 Zero-Days

CWE-918, CWE-22, CWE-306, CWE-284

Timeline of Actively Exploited SonicWall SMA1000 Zero-Days

  • Rapid7 MDR assesses active, targeted exploitation of internet-facing SonicWall SMA1000 appliances began at least this late in June 2026.
  • Rapid7 MDR team directly observes active exploitation of SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) against a customer environment.
  • SonicWall publishes official security advisory and patches for CVE-2026-15409 and CVE-2026-15410; Microsoft ships July 2026 Patch Tuesday fixing 570 vulnerabilities including zero-days CVE-2026-56164 (SharePoint), CVE-2026-56155 (AD FS), and CVE-2026-50661 (BitLocker).
  • Mandiant/Google FLARE and CISA publicly confirm active in-the-wild exploitation of the SharePoint Server zero-day (CVE-2026-56164) and functional exploit code observed for the AD FS zero-day (CVE-2026-56155), prompting emergency advisories separate from the routine Patch Tuesday release.
  • Rapid7 publishes detailed technical analysis of the SonicWall exploit chain and IOCs; CISA adds CVE-2026-15409, CVE-2026-15410, CVE-2026-56164, and CVE-2026-56155 to the Known Exploited Vulnerabilities catalog.
  • Additional indicators of compromise for the SonicWall SMA1000 campaign are identified and published by multiple security vendors, including Rapid7's blog update adding attacker workstation asset names (DESKTOP-KRLUI3J, DESKTOP-IC3C80F, DESKTOP-5P0TSCP, KALI) tied to sessions authenticated with harvested SMA1000 credentials.
  • S-RM Cyber Intelligence Briefing publishes summary advisory covering both the SonicWall SMA1000 and Microsoft July 2026 Patch Tuesday events, prompting this threat record.
  • CISA-mandated deadline for U.S. Federal Civilian Executive Branch agencies to remediate the SonicWall SMA1000 KEV entries.

Sources cited for Actively Exploited SonicWall SMA1000 Zero-Days

Threats related to Actively Exploited SonicWall SMA1000 Zero-Days

Detection coverage for TL-2026-1451

As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1451 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats