Critical SonicWall SSRF Zero-Day Opens WebSocket Tunnel to Internal Services
ID: ba689872-3fb8-5b17-8092-0c71cff15fc6
STIX ID: report--ba689872-3fb8-5b17-8092-0c71cff15fc6
Feed Name: Cyber Press
SonicWall disclosed two actively exploited zero-day vulnerabilities in SMA1000 Series appliances — a critical SSRF (CVE-2026-15409) that can tunnel to localhost services and a path-traversal/code-execution flaw in ctrl-service (CVE-2026-15410) that can run arbitrary hotfixes as root. Rapid7 observed targeted exploitation used to harvest credentials, session DBs, and TOTP seeds for persistent, stealthy access; public PoCs exist and CISA added the CVEs to its KEV catalog. SonicWall issued platform hotfixes and recommends forensic review, reimaging compromised appliances, and resetting credentials and MFA seeds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
