logo

SonicWall SMA1000 Flaws Actively Exploited for SSRF and Remote Code Execution

ID: 294c4b84-1725-5d0e-b5b7-cb2fec6e5ea0

STIX ID: report--294c4b84-1725-5d0e-b5b7-cb2fec6e5ea0

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Tamilselvan

...
...

SonicWall issued an urgent advisory confirming active exploitation of two SMA1000 vulnerabilities — an unauthenticated SSRF (CVE-2026-15409) and an authenticated code-injection (CVE-2026-15410) — which can be chained to achieve full remote code execution on affected SMA1000 6210/7210/8200v appliances running specified firmware versions. The advisory provides IOCs (suspicious API requests, wsproxy anomalies, hotfix rollback path-traversal entries, and unauthorized routes), instructs immediate upgrades to fixed hotfix versions (12.4.3-03453 or 12.5.0-02835 or later), and recommends forensic review, re-imaging, credential rotation, and TOTP resets if compromise is detected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.