CVE-2026-15410 and CVE-2026-15409: SonicWall SMA 1000 Zero-Days Exploited in the Wild
ID: 6a6b7488-67f4-55eb-8e4b-448226a30b57
STIX ID: report--6a6b7488-67f4-55eb-8e4b-448226a30b57
Feed Name: SOC Prime Blog
Two actively exploited zero-day vulnerabilities in SonicWall SMA 1000 Series appliances (CVE-2026-15409 SSRF and CVE-2026-15410 post-auth code injection) have been observed chained in the wild to gain pre-auth footholds, execute administrative OS commands, steal credentials and TOTP seeds, and pivot into internal infrastructure; SonicWall released hotfixes for affected firmware, CISA added the flaws to its KEV catalog, and vendor guidance recommends immediate patching plus forensic review, re-imaging/redeployment, password rotation, and TOTP resets, while public IOCs (log entries, rollback artifacts, suspicious /__api__ and /wsproxy requests) aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
