logo

CVE-2026-15410 and CVE-2026-15409: SonicWall SMA 1000 Zero-Days Exploited in the Wild

ID: 6a6b7488-67f4-55eb-8e4b-448226a30b57

STIX ID: report--6a6b7488-67f4-55eb-8e4b-448226a30b57

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-23

Author: SOC Prime Team

...
...

Two actively exploited zero-day vulnerabilities in SonicWall SMA 1000 Series appliances (CVE-2026-15409 SSRF and CVE-2026-15410 post-auth code injection) have been observed chained in the wild to gain pre-auth footholds, execute administrative OS commands, steal credentials and TOTP seeds, and pivot into internal infrastructure; SonicWall released hotfixes for affected firmware, CISA added the flaws to its KEV catalog, and vendor guidance recommends immediate patching plus forensic review, re-imaging/redeployment, password rotation, and TOTP resets, while public IOCs (log entries, rollback artifacts, suspicious /__api__ and /wsproxy requests) aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.