logo

Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root

ID: b9faf5a3-2e99-565f-ac0c-f2fead117064

STIX ID: report--b9faf5a3-2e99-565f-ac0c-f2fead117064

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Divya

...
...

Rapid7 observed active exploitation of two zero-day vulnerabilities in SonicWall SMA 1000 Series appliances—CVE-2026-15409 (CVSS 10.0) enables an unauthenticated WebSocket-based SSRF to access internal services (e.g., Erlang on localhost:1050), and CVE-2026-15410 allows privilege escalation via a path-traversal in the ctrl-service rollback flow to execute a malicious script as root; the flaws have been added to CISA’s Known Exploited Vulnerabilities catalog, SonicWall released hotfixes (12.4.3-03453 / 12.5.0-02835 or later), and organizations are advised to patch immediately, investigate appliances for compromise, re-image or redeploy as needed, and rotate credentials/TOTP tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.