Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP) — Threadlinqs Intelligence
As of 2026-07-17, Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1451 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
SonicWall disclosed and patched two actively exploited SMA1000 zero-days — a pre-auth CVSS 10.0 SSRF (CVE-2026-15409) chained with a post-auth path-traversal code injection (CVE-2026-15410) — that
This threat bundles two concurrent, high-severity vendor patch events from mid-July 2026 that both demand urgent perimeter and identity-infrastructure remediation.
SonicWall SMA1000: Rapid7 MDR observed active, targeted exploitation of internet-facing SMA1000-series appliances (models 6210, 7210, 8200v) beginning as early as late June 2026, with confirmed exploitation activity from July 9, 2026. Attackers chain two flaws. CVE-2026-15409 (CVSS 10.0) is a server-side request forgery in the WorkPlace websocket proxy feature (/wsproxy, port 443) that lets an unauthenticated remote attacker supply a localhost-pointing host value, causing the appliance to reach less-hardened internal-only services — notably an Erlang process listening on localhost:1050 — without any credentials. Once that internal foothold is established, CVE-2026-15410 is a post-authentication path-traversal / code-injection vulnerability in the remove_hotfix workflow of the ctrl-service (port 8188, Appliance Management Console); supplying a malicious hotfix path containing directory-traversal sequences (e.g. ../../../../../../tmp/payload.sh) causes the AMC to execute the attacker's script as root. SonicWall confirmed there is no workaround — only patching remediates. Post-compromise, threat actors harvested high-value credentials, active VPN session databases, and TOTP MFA seed configurations from the appliance, then used those credentials to move laterally, including anomalous VPN-less Active Directory authentications against core domain controllers originating from the appliance's internal IP address — effectively using the SMA1000 as an undetected backdoor into the internal AD environment. CISA added both CVEs to the KEV catalog with a July 17, 2026 FCEB remediation deadline. Patched versions: 12.4.3-03453 (platform-hotfix) or later, and 12.5.0-02835 (platform-hotfix) or later.
Microsoft July 2026 Patch Tuesday: Microsoft shipped fixes for a record 570 vulnerabilities (breakdown: 254 Elevation of Privilege, 145 Remote Code Execution, 102 Information Disclosure, 35 Denial of Service, 17 Security Feature Bypass, 16 Spoofing; 59 rated Critical, 48 of those RCE). Microsoft attributed the unprecedented volume in part to a newly deployed AI-powered vulnerability-discovery system scanning the Windows codebase proactively. Three zero-days were addressed: CVE-2026-56164, an unauthenticated elevation-of-privilege in SharePoint Server (2016, 2019, Subscription Edition) caused by a missing authentication check (CWE-306) in the User Profiles assembly that lets an unauthenticated network attacker escalate to Farm Administrator by omitting the security digest and supplying crafted routing headers — discovered by Mandiant/Google FLARE during real-world incident response and actively exploited despite a deceptively low CVSS of 5.3; CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS) rooted in insufficiently granular Distributed Key Management (DKM) container ACLs that lets a low-privileged authenticated local attacker reach administrator level and potentially expose the private keys backing an organization's federation tokens, with functional exploit code observed in the wild (CVSS 7.8); and CVE-2026-50661, a publicly disclosed (not yet observed exploited) BitLocker security-feature-bypass. Both CVE-2026-56164 and CVE-2026-56155 were added to CISA KEV. Interim mitigation for the SharePoint flaw includes enabling AMSI integration with Full Request Body Scan mode pending patch deployment on internet-facing farms.
Together, these events represent a coordinated pressure point on perimeter VPN/SSL-VPN appliances and core identity infrastructure (AD FS, SharePoint) in the same week, raising the likelihood of opportunistic and targeted follow-on exploitation by multiple threat clusters before organizations complete patching.
Weaknesses (CWE)
CWE-918, CWE-22, CWE-306, CWE-284
Target sectors: government administration, finance, health, technology, education, critical-infrastructure, professional-services
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-15409, CVE-2026-15410, CVE-2026-56164, CVE-2026-56155, CVE-2026-50661, T1190, T1059, T1059.004, T1078, T1505, T1068, T1548, T1211, T1083, T1555