logo

SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

ID: 8d8b2cfa-6438-5635-9b03-33b2d6b462f3

STIX ID: report--8d8b2cfa-6438-5635-9b03-33b2d6b462f3

Feed Name: CosmicBytez Labs

Threat Score
95/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

...
...

**Executive summary:** SonicWall has disclosed two critical vulnerabilities in SMA1000 appliances (CVE-2026-15409 SSRF and CVE-2026-15410 post-auth command injection) that are being actively chained and exploited in the wild to achieve full remote compromise of edge devices used by governments and enterprises; patches are available (12.4.3-03453 / 12.5.0-02835), there are no workarounds, and CISA has added the issues to its KEV catalog with an urgent remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.