Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)
Actively Exploited SonicWall SMA1000 Zero-Days (TL-2026-1451) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-17. It has no confirmed attribution, affects SonicWall SMA1000 (Secure Mobile Access), references 5 CVEs (CVE-2026-15409, CVE-2026-15410, CVE-2026-56164), maps to 23 MITRE ATT&CK techniques (T1005, T1021, T1021.004), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1451
- Threat ID
- TL-2026-1451
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-17
- Last reviewed
- 2026-07-17
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, critical-infrastructure, professional-services
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 27
SonicWall disclosed and patched two actively exploited SMA1000 zero-days — a pre-auth CVSS 10.0 SSRF (CVE-2026-15409) chained with a post-auth path-traversal code injection (CVE-2026-15410) — that attackers used to gain root on internet-facing appliances, harvest credentials/TOTP seeds, and pivot into Active Directory. Concurrently, Microsoft's record-breaking July 2026 Patch Tuesday fixed 570 vulnerabilities including two actively exploited zero-days (SharePoint Server CVE-2026-56164, AD FS CVE-2026-56155) and one publicly disclosed BitLocker bypass (CVE-2026-50661), a volume Microsoft attributes to its new AI-powered vulnerability-discovery tooling.
How Actively Exploited SonicWall SMA1000 Zero-Days works
This threat bundles two concurrent, high-severity vendor patch events from mid-July 2026 that both demand urgent perimeter and identity-infrastructure remediation.
SonicWall SMA1000: Rapid7 MDR observed active, targeted exploitation of internet-facing SMA1000-series appliances (models 6210, 7210, 8200v) beginning as early as late June 2026, with confirmed exploitation activity from July 9, 2026. Attackers chain two flaws. CVE-2026-15409 (CVSS 10.0) is a server-side request forgery in the WorkPlace websocket proxy feature (/wsproxy, port 443) that lets an unauthenticated remote attacker supply a localhost-pointing host value, causing the appliance to reach less-hardened internal-only services — notably an Erlang process listening on localhost:1050 — without any credentials. Once that internal foothold is established, CVE-2026-15410 is a post-authentication path-traversal / code-injection vulnerability in the remove_hotfix workflow of the ctrl-service (port 8188, Appliance Management Console); supplying a malicious hotfix path containing directory-traversal sequences (e.g. ../../../../../../tmp/payload.sh) causes the AMC to execute the attacker's script as root. SonicWall confirmed there is no workaround — only patching remediates. Post-compromise, threat actors harvested high-value credentials, active VPN session databases, and TOTP MFA seed configurations from the appliance, then used those credentials to move laterally, including anomalous VPN-less Active Directory authentications against core domain controllers originating from the appliance's internal IP address — effectively using the SMA1000 as an undetected backdoor into the internal AD environment. CISA added both CVEs to the KEV catalog with a July 17, 2026 FCEB remediation deadline. Patched versions: 12.4.3-03453 (platform-hotfix) or later, and 12.5.0-02835 (platform-hotfix) or later.
Microsoft July 2026 Patch Tuesday: Microsoft shipped fixes for a record 570 vulnerabilities (breakdown: 254 Elevation of Privilege, 145 Remote Code Execution, 102 Information Disclosure, 35 Denial of Service, 17 Security Feature Bypass, 16 Spoofing; 59 rated Critical, 48 of those RCE). Microsoft attributed the unprecedented volume in part to a newly deployed AI-powered vulnerability-discovery system scanning the Windows codebase proactively. Three zero-days were addressed: CVE-2026-56164, an unauthenticated elevation-of-privilege in SharePoint Server (2016, 2019, Subscription Edition) caused by a missing authentication check (CWE-306) in the User Profiles assembly that lets an unauthenticated network attacker escalate to Farm Administrator by omitting the security digest and supplying crafted routing headers — discovered by Mandiant/Google FLARE during real-world incident response and actively exploited despite a deceptively low CVSS of 5.3; CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS) rooted in insufficiently granular Distributed Key Management (DKM) container ACLs that lets a low-privileged authenticated local attacker reach administrator level and potentially expose the private keys backing an organization's federation tokens, with functional exploit code observed in the wild (CVSS 7.8); and CVE-2026-50661, a publicly disclosed (not yet observed exploited) BitLocker security-feature-bypass. Both CVE-2026-56164 and CVE-2026-56155 were added to CISA KEV. Interim mitigation for the SharePoint flaw includes enabling AMSI integration with Full Request Body Scan mode pending patch deployment on internet-facing farms.
Together, these events represent a coordinated pressure point on perimeter VPN/SSL-VPN appliances and core identity infrastructure (AD FS, SharePoint) in the same week, raising the likelihood of opportunistic and targeted follow-on exploitation by multiple threat clusters before organizations complete patching.
MITRE ATT&CK techniques used in TL-2026-1451
Collection
Lateral Movement
T1021 Remote Services; T1021.004 SSH; T1550 Use Alternate Authentication Material
Discovery
T1046 Network Service Discovery; T1087.002 Domain Account
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Persistence
T1078 Valid Accounts; T1505 Server Software Component
discovery
T1083 File and Directory Discovery
Command and Control
T1090 Proxy; T1090.001 Internal Proxy
Credential Access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1558 Steal or Forge Kerberos Tickets
Initial Access
T1190 Exploit Public-Facing Application
Defense Evasion
T1211 Exploitation for Stealth
Impact
Reconnaissance
Affected products and versions in Actively Exploited SonicWall SMA1000 Zero-Days
- SonicWall — SMA1000 (Secure Mobile Access)
Vulnerable versions: 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800
Fixed in: 12.4.3-03453 (platform-hotfix) or later; 12.5.0-02835 (platform-hotfix) or later - SonicWall — SMA 1000 Series appliance models
Vulnerable versions: 6210; 7210; 8200v - Microsoft — SharePoint Server
Vulnerable versions: SharePoint Server 2016; SharePoint Server 2019; SharePoint Server Subscription Edition
Fixed in: July 14, 2026 cumulative security update - Microsoft — Windows Server (Active Directory Federation Services)
Vulnerable versions: Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022; Windows Server 2025
Fixed in: July 14, 2026 security update - Microsoft — Windows (BitLocker)
Vulnerable versions: Windows versions supporting BitLocker prior to July 2026 update
Fixed in: July 14, 2026 security update
Remediation for Actively Exploited SonicWall SMA1000 Zero-Days
Patches
- SonicWall SMA1000 12.4.3-03453 (platform-hotfix) or later
- SonicWall SMA1000 12.5.0-02835 (platform-hotfix) or later
- Microsoft July 2026 Patch Tuesday cumulative update (KB covering CVE-2026-56164, CVE-2026-56155, CVE-2026-50661)
- Microsoft KB5121391 (AD FS DKM container ACL hardening for CVE-2026-56155)
Immediate actions
- Patch SonicWall SMA1000 appliances to 12.4.3-03453 (platform-hotfix) or later, or 12.5.0-02835 (platform-hotfix) or later
- Patch Microsoft SharePoint Server (2016, 2019, Subscription Edition) with the July 14, 2026 security update addressing CVE-2026-56164
- Apply the July 14, 2026 Windows Server security update addressing CVE-2026-56155 (AD FS) across Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025
- Perform forensic analysis of internet-facing SMA1000 appliances for signs of prior compromise before/after patching
- Rotate all credentials, VPN session tokens, and TOTP MFA seeds stored on or accessible via SMA1000 appliances that were internet-facing prior to patching
- Review Active Directory authentication logs for anomalous VPN-less logons to domain controllers originating from SMA1000 appliance internal IPs (Event ID 4624, logon type 3)
Workarounds
- None available for SonicWall SMA1000 flaws — SonicWall confirmed no workaround exists
- Enable AMSI integration with Full Request Body Scan mode as interim mitigation for CVE-2026-56164 on internet-facing SharePoint farms pending patch
Longer-term hardening
- Harden AD FS Distributed Key Management (DKM) container ACLs per Microsoft KB5121391 guidance ahead of the October enforcement deadline
- Deploy EDR/NDR with behavioral detection on appliance management interfaces and identity infrastructure
- Segment SSL-VPN/SMA appliance management interfaces from direct internet exposure
- Establish routine patch cadence tracking for CISA KEV additions affecting perimeter and identity systems
CVEs associated with Actively Exploited SonicWall SMA1000 Zero-Days
CVE-2026-15409, CVE-2026-15410, CVE-2026-56164, CVE-2026-56155, CVE-2026-50661
Weaknesses (CWE) in Actively Exploited SonicWall SMA1000 Zero-Days
CWE-918, CWE-22, CWE-306, CWE-284
Timeline of Actively Exploited SonicWall SMA1000 Zero-Days
- Rapid7 MDR assesses active, targeted exploitation of internet-facing SonicWall SMA1000 appliances began at least this late in June 2026.
- Rapid7 MDR team directly observes active exploitation of SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) against a customer environment.
- SonicWall publishes official security advisory and patches for CVE-2026-15409 and CVE-2026-15410; Microsoft ships July 2026 Patch Tuesday fixing 570 vulnerabilities including zero-days CVE-2026-56164 (SharePoint), CVE-2026-56155 (AD FS), and CVE-2026-50661 (BitLocker).
- Mandiant/Google FLARE and CISA publicly confirm active in-the-wild exploitation of the SharePoint Server zero-day (CVE-2026-56164) and functional exploit code observed for the AD FS zero-day (CVE-2026-56155), prompting emergency advisories separate from the routine Patch Tuesday release.
- Rapid7 publishes detailed technical analysis of the SonicWall exploit chain and IOCs; CISA adds CVE-2026-15409, CVE-2026-15410, CVE-2026-56164, and CVE-2026-56155 to the Known Exploited Vulnerabilities catalog.
- Additional indicators of compromise for the SonicWall SMA1000 campaign are identified and published by multiple security vendors, including Rapid7's blog update adding attacker workstation asset names (DESKTOP-KRLUI3J, DESKTOP-IC3C80F, DESKTOP-5P0TSCP, KALI) tied to sessions authenticated with harvested SMA1000 credentials.
- S-RM Cyber Intelligence Briefing publishes summary advisory covering both the SonicWall SMA1000 and Microsoft July 2026 Patch Tuesday events, prompting this threat record.
- CISA-mandated deadline for U.S. Federal Civilian Executive Branch agencies to remediate the SonicWall SMA1000 KEV entries.
Sources cited for Actively Exploited SonicWall SMA1000 Zero-Days
- Critical vulnerabilities drive urgent patching across SonicWall and Microsoft products
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
- Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
- SonicWall SMA1000 zero-days exploited in targeted attacks
- SonicWall issues urgent patches for two actively exploited zero-day vulnerabilities in SMA 1000 appliances
- Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
- SonicWall warns of active exploitation of two SMA 1000 zero-days
- SonicWall SMA1000 Zero-Days Threat Alert
- SonicWall SMA 1000 Zero-Days Are Being Exploited Right Now
- SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- Microsoft July Patch Tuesday Fixes Record 570 Vulnerabilities and Three Exploited Zero-Days
- Microsoft Fixes Record 570 Security Flaws in Biggest Patch Tuesday Ever
- Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days
Threats related to Actively Exploited SonicWall SMA1000 Zero-Days
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem
Detection coverage for TL-2026-1451
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1451 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.