Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has issued a warning about the active exploitation of two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances, with one flaw allowing arbitrary command execution. Urgent patches have been released, and CISA has added these vu…
Intelligence analysis by Gemini 2.5 Flash

Two critical zero-day vulnerabilities, CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-authentication code injection, CVSS 7.2), are being actively exploited in SonicWall SMA 1000 devices. SonicWall has released hotfixes and provided indicators of compromise, urging customers to patch immediately and conduct forensic analysis, a call reinforced by CISA's mandate for federal …
Imagine your house has a special door that lets you get in from far away, like when you're on vacation. Bad guys found two secret ways (called zero-days) to pick the lock on this special door, and one of them is so good it lets them take over your whole house, like getting the master key! The company that made the door quickly made new, stronger locks (patches) and told everyone to install them super fast, like fixing a broken window before a big storm hits. The government even told its own offices to fix their doors by a certain date because it's so important.
Analysis
Critical Flaws in Remote Access
SonicWall has confirmed the active exploitation of two significant zero-day vulnerabilities impacting its Secure Mobile Access (SMA) 1000 series appliances. The more critical of the two, CVE-2026-15409, is a Server-side Request Forgery (SSRF) vulnerability with a maximum CVSS score of 10.0. This flaw allows a remote, unauthenticated attacker to potentially force the appliance to make requests to unintended locations, which can be a precursor to further, more damaging attacks.
The second vulnerability, CVE-2026-15410, is a post-authentication code injection flaw within the Appliance Management Console (AMC), rated with a CVSS score of 7.2. While it requires prior authentication, it enables a remote authenticated attacker to execute arbitrary operating system commands as an administrator under specific conditions. The combination of these vulnerabilities presents a formidable threat, as an attacker could potentially chain them or leverage existing credentials to gain deep control over affected systems.
Active Exploitation and Mitigation
SonicWall explicitly stated it has "investigated multiple cases indicating the active exploitation of the vulnerabilities," emphasizing the immediate danger. In response, the company has promptly released patches, available in versions 12.4.3-03453 (platform-hotfix) and 12.5.0-02835 (platform-hotfix), and higher versions for both. Customers are strongly advised to apply these fixes without delay to mitigate the risk of compromise.
Beyond patching, SonicWall has also provided crucial indicators of compromise (IoCs) to help organizations detect if their systems have already been breached. These IoCs include specific requests in extraweb_access.log to /__api__/login or /__api__/logout with HTTP 200 status, suspicious host parameters in /wsproxy requests, hotfix rollbacks in ctrl-service.log, or the presence of specific URIs in /var/lib/unit/conf.json. If any IoCs are found, the recommendation is to re-image physical appliances or redeploy virtual ones, reset all user and administrator passwords, and refresh time-based one-time password tokens.
Regulatory Urgency and Broader Impact
The severity and active exploitation of these zero-days have prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates that all Federal Civilian Executive Branch (FCEB) agencies apply the necessary fixes by July 17, 2026. This swift action by CISA underscores the critical nature of these vulnerabilities and the immediate threat they pose to government and critical infrastructure.
While the CISA directive specifically targets federal agencies, its implications extend to all organizations globally utilizing SonicWall SMA 1000 series appliances. The mandate serves as a clear signal that these are not theoretical threats but actively exploited pathways for attackers. Therefore, all enterprises, regardless of their sector, should treat these vulnerabilities with the highest priority, ensuring timely patching and thorough security assessments to protect their remote access infrastructure from potential breaches and unauthorized access.
Key points
- Two zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in SonicWall SMA 1000 series appliances are under active exploitation.
- CVE-2026-15409 is a critical Server-side Request Forgery (SSRF) flaw (CVSS 10.0) allowing remote unauthenticated requests.
- CVE-2026-15410 is a post-authentication code injection vulnerability (CVSS 7.2) enabling arbitrary OS command execution as administrator.
- SonicWall has released hotfixes (versions 12.4.3-03453 and 12.5.0-02835 and higher) and urges immediate application.
- CISA has added these flaws to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by July 17, 2026.
If organizations promptly apply the released patches and follow SonicWall's guidance for forensic analysis, they can effectively mitigate the immediate threat posed by these actively exploited zero-days. The rapid response from SonicWall and CISA's swift inclusion in the KEV catalog will help ensure widespread awareness and accelerate the adoption of necessary security measures, potentially preventing further widespread compromises.
Organizations that delay patching or fail to conduct thorough forensic analysis risk continued exposure to these critical vulnerabilities, which are already being actively exploited. This could lead to unauthorized access, data breaches, and significant disruption to remote access capabilities, potentially allowing attackers to establish persistent footholds within their networks.



