SonicWall has issued a critical warning regarding the exploitation of two vulnerabilities in its SMA1000 series, identified as CVE-2026-15409 and CVE-2026-15410. These zero-day vulnerabilities are being exploited in active attacks, prompting SonicWall to strongly recommend that customers implement the newly released security updates immediately.
CVE-2026-15409 is a critical server-side request forgery (SSRF) vulnerability (CVSS 10.0) located in the workplace interface of the SMA1000 appliance. This flaw enables an unauthenticated remote attacker to trigger the appliance to send requests to unauthorized locations.
CVE-2026-15410 is a high-severity code injection vulnerability (CVSS 7.2) in the SMA1000 Appliance Management Console. This issue allows a remote authenticated administrator to execute arbitrary operating system commands, posing significant risks to system security.
Despite requiring administrative privileges, SonicWall has assigned a devastating overall CVSS score of 10.0 to this advisory. The company has confirmed that it is actively investigating multiple instances of exploitation associated with these vulnerabilities.
“SonicWall PSIRT has confirmed multiple exploitations of the vulnerabilities mentioned in this alert,” SonicWall cautioned.
“We strongly advocate that customers promptly upgrade to the hotfix release to mitigate these vulnerabilities.”
To date, SonicWall has not clarified whether attackers are using these vulnerabilities in conjunction. BleepingComputer has reached out for further details and will provide updates as they are received.
These vulnerabilities exist in platform hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. The fix is available in platform hotfix versions 12.4.3-03453 and 12.5.0-02835 and later versions.
SonicWall indicates that these vulnerabilities do not impact SSL-VPN or the SMA 100 series product line operating on SonicWall firewalls.
The company has also released indicators of compromise (IOCs) that administrators can use to check for signs of compromise:
- If
extraweb_access.logshows requests to/__api__/loginor/__api__/logoutwith an HTTP 200 status - If
extraweb_access.logshows requests to/wsproxywith a suspicious host parameter and an HTTP status of 101 - If
ctrl-service.logcontains hotfix rollbacks with path traversal names - If
/var/lib/unit/conf.jsonhas routes/__api__/loginor/__api__/logout(these URIs should not exist in the canonical configuration)
SonicWall strongly urges users to upgrade to the latest hotfix and conduct a thorough analysis for the presence of the aforementioned IOCs.
If any signs of compromise are detected, the company advises administrators to reimage the physical appliance or redeploy the virtual appliance, reset all user and administrator passwords, and regenerate TOTP tokens.
SonicWall further emphasizes that there are no viable workarounds or mitigations for these vulnerabilities other than applying hotfixes.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included both vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog and corroborated that they are actively being exploited in cyberattacks.
Federal agencies have until July 17, 2026, to secure their systems as mandated under Binding Operating Order (BOD) 26-04 or to remove the affected products if protective measures cannot be implemented.
Research indicates that security teams only document 54% of successful attacks and issue warnings for just 14%. The rest remain undetected within the network.
Picus’ whitepaper demonstrates how to evaluate your SIEM and EDR rules through breach and attack simulations to ensure that potential threats are properly addressed.
Source: www.bleepingcomputer.com




