logo

SonicWall warns of active exploitation of two SMA 1000 zero-days

ID: 508e6aab-5fb1-54c4-84b8-c65c2a62e510

STIX ID: report--508e6aab-5fb1-54c4-84b8-c65c2a62e510

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

SonicWall warns that two zero-day vulnerabilities in SMA1000 appliances—CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-auth code injection, CVSS 7.2)—are being actively exploited; the advisory lists affected versions, available hotfix releases, recommended log/IOC checks (unusual API requests, suspicious WebSocket proxy connections, path traversal/hotfix rollback evidence, unauthorized API routes), and urges immediate patching and full forensic remediation if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.