Hackers Actively Exploiting SonicWall SMA1000 0-Day Vulnerability in the Wild
ID: ed7eb127-f44b-59f6-a521-e055a63d2b23
STIX ID: report--ed7eb127-f44b-59f6-a521-e055a63d2b23
Feed Name: cybersecurityNews.com
Threat Score
#### Executive summary: The report details two critical vulnerabilities in SonicWall SMA1000 appliances (CVE-2026-15409 SSRF and CVE-2026-15410 local privilege escalation) that are being actively exploited to achieve unauthenticated remote code execution and full root compromise via the /wsproxy websocket proxy and a hardcoded Erlang cookie; investigators observed credential/TOTP theft, AD pivoting, and provide IOCs and urgent patching guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
