SonicWall says attackers are actively exploiting two previously unpatched flaws in its SMA1000 secure remote-access appliances, and customers should install emergency updates now. The bugs are CVE-2026-15409, a critical server-side request forgery issue in the Work Place interface that can be triggered remotely without logging in, and CVE-2026-15410, a code-injection flaw in the Management Console that requires an authenticated administrator. Affected SMA1000 models include the 6210, 7210, and 8200v on specified 12.4.3 and 12.5.0 hotfix builds; fixes are in 12.4.3-03453 and 12.5.0-02835 and later.
Sergiu Gatlan
2026.08.10
96% relevant
This is a direct update to the same underlying SMA1000 event and adds the important new detail that CISA now says ransomware gangs, not just earlier zero-day attackers, are exploiting CVE-2026-15409 and CVE-2026-15410.
info@thehackernews.com (The Hacker News)
2026.08.03
95% relevant
This appears to be a direct update on the same underlying event: active exploitation of SonicWall SMA1000 zero-days. The new detail is that INC ransomware is emerging as a primary observed actor exploiting the flaws, adding threat-actor attribution and likely follow-on impact for affected organizations.
Ionut Arghire
2026.08.03
96% relevant
This source updates the same SMA1000 zero-day exploitation event by adding attribution from Resecurity that INC Ransomware is now the most active actor chaining CVE-2026-15409 and CVE-2026-15410, and that victims are receiving follow-up negotiation emails and phone calls tied to the intrusions.
info@thehackernews.com (The Hacker News)
2026.07.15
99% relevant
This article appears to cover the same underlying event: SonicWall's disclosure that two SMA 1000 zero-days are being exploited, including one that can allow execution of administrator commands on affected secure remote-access appliances.
Eduard Kovacs
2026.07.15
99% relevant
This article is the same underlying event and adds specific patch and remediation details, including the hotfix versions 12.4.3-03453 and 12.5.0-02835, affected SMA1000 models, SonicWall’s note that multiple exploitation cases were investigated, and that CISA added both CVEs to KEV with a July 17 deadline for agencies.
Lawrence Abrams
2026.07.14
100% relevant
This article establishes a distinct new story by identifying a new set of actively exploited SonicWall zero-days affecting SMA1000 appliances, separate from the existing tracked story about SonicWall Gen6 SSL-VPN MFA bypass CVE-2024-12802.