SonicWall says attackers are exploiting SMA1000 zero-day flaws CVE-2026-15409 and CVE-2026-15410

SonicWall says attackers are actively exploiting two previously unpatched flaws in its SMA1000 secure remote-access appliances, and customers should install emergency updates now. The bugs are CVE-2026-15409, a critical server-side request forgery issue in the Work Place interface that can be triggered remotely without logging in, and CVE-2026-15410, a code-injection flaw in the Management Console that requires an authenticated administrator. Affected SMA1000 models include the 6210, 7210, and 8200v on specified 12.4.3 and 12.5.0 hotfix builds; fixes are in 12.4.3-03453 and 12.5.0-02835 and later.
Why it matters: These devices sit at the edge of corporate networks, so active exploitation can put remote access infrastructure at immediate risk. Organizations using SMA1000 should patch now, check SonicWall’s indicators of compromise, and if compromise is found, re-image or redeploy appliances and reset passwords and TOTP tokens.

Sources

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
Sergiu Gatlan 2026.08.10 96% relevant
This is a direct update to the same underlying SMA1000 event and adds the important new detail that CISA now says ransomware gangs, not just earlier zero-day attackers, are exploiting CVE-2026-15409 and CVE-2026-15410.
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
info@thehackernews.com (The Hacker News) 2026.08.03 95% relevant
This appears to be a direct update on the same underlying event: active exploitation of SonicWall SMA1000 zero-days. The new detail is that INC ransomware is emerging as a primary observed actor exploiting the flaws, adding threat-actor attribution and likely follow-on impact for affected organizations.
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
Ionut Arghire 2026.08.03 96% relevant
This source updates the same SMA1000 zero-day exploitation event by adding attribution from Resecurity that INC Ransomware is now the most active actor chaining CVE-2026-15409 and CVE-2026-15410, and that victims are receiving follow-up negotiation emails and phone calls tied to the intrusions.
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
info@thehackernews.com (The Hacker News) 2026.07.15 99% relevant
This article appears to cover the same underlying event: SonicWall's disclosure that two SMA 1000 zero-days are being exploited, including one that can allow execution of administrator commands on affected secure remote-access appliances.
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
Eduard Kovacs 2026.07.15 99% relevant
This article is the same underlying event and adds specific patch and remediation details, including the hotfix versions 12.4.3-03453 and 12.5.0-02835, affected SMA1000 models, SonicWall’s note that multiple exploitation cases were investigated, and that CISA added both CVEs to KEV with a July 17 deadline for agencies.
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
Lawrence Abrams 2026.07.14 100% relevant
This article establishes a distinct new story by identifying a new set of actively exploited SonicWall zero-days affecting SMA1000 appliances, separate from the existing tracked story about SonicWall Gen6 SSL-VPN MFA bypass CVE-2024-12802.
← Back to all stories