SonicWall warns of active exploitation of two SMA 1000 zero-days
ID: 508e6aab-5fb1-54c4-84b8-c65c2a62e510
STIX ID: report--508e6aab-5fb1-54c4-84b8-c65c2a62e510
Feed Name: Security Affairs
SonicWall warns that two zero-day vulnerabilities in SMA1000 appliances—CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-auth code injection, CVSS 7.2)—are being actively exploited; the advisory lists affected versions, available hotfix releases, recommended log/IOC checks (unusual API requests, suspicious WebSocket proxy connections, path traversal/hotfix rollback evidence, unauthorized API routes), and urges immediate patching and full forensic remediation if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
