logo

Hackers Actively Exploiting SonicWall SMA1000 0-Day Vulnerability in the Wild

ID: ed7eb127-f44b-59f6-a521-e055a63d2b23

STIX ID: report--ed7eb127-f44b-59f6-a521-e055a63d2b23

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

Author: Guru Baran

...
...

#### Executive summary: The report details two critical vulnerabilities in SonicWall SMA1000 appliances (CVE-2026-15409 SSRF and CVE-2026-15410 local privilege escalation) that are being actively exploited to achieve unauthenticated remote code execution and full root compromise via the /wsproxy websocket proxy and a hardcoded Erlang cookie; investigators observed credential/TOTP theft, AD pivoting, and provide IOCs and urgent patching guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.