SonicWall says attackers are actively exploiting two previously unpatched flaws in its SMA1000 secure remote-access appliances, and customers should install emergency updates now. The bugs are CVE-2026-15409, a critical server-side request forgery issue in the Work Place interface that can be triggered remotely without logging in, and CVE-2026-15410, a code-injection flaw in the Management Console that requires an authenticated administrator. Affected SMA1000 models include the 6210, 7210, and 8200v on specified 12.4.3 and 12.5.0 hotfix builds; fixes are in 12.4.3-03453 and 12.5.0-02835 and later.
Why it matters: These devices sit at the edge of corporate networks, so active exploitation can put remote access infrastructure at immediate risk. Organizations using SMA1000 should patch now, check SonicWall’s indicators of compromise, and if compromise is found, re-image or redeploy appliances and reset passwords and TOTP tokens.
info@thehackernews.com (The Hacker News)
2026.07.15
99% relevant
This article appears to cover the same underlying event: SonicWall's disclosure that two SMA 1000 zero-days are being exploited, including one that can allow execution of administrator commands on affected secure remote-access appliances.
Eduard Kovacs
2026.07.15
99% relevant
This article is the same underlying event and adds specific patch and remediation details, including the hotfix versions 12.4.3-03453 and 12.5.0-02835, affected SMA1000 models, SonicWall’s note that multiple exploitation cases were investigated, and that CISA added both CVEs to KEV with a July 17 deadline for agencies.
Lawrence Abrams
2026.07.14
100% relevant
This article establishes a distinct new story by identifying a new set of actively exploited SonicWall zero-days affecting SMA1000 appliances, separate from the existing tracked story about SonicWall Gen6 SSL-VPN MFA bypass CVE-2024-12802.
← Back to all stories