logo

SonicWall SMA zero-days were exploited weeks before disclosure

ID: a5bc65a0-182b-5838-a246-ff1aa464aab4

STIX ID: report--a5bc65a0-182b-5838-a246-ff1aa464aab4

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Zeljka Zorz

...
...

Volexity disclosed that two SonicWall SMA 1000 zero-days (CVE-2026-15409 SSRF and CVE-2026-15410 code injection) were exploited in the wild to tunnel to localhost services, gain root, and install in-memory Java-based backdoors and a proxy to capture credentials and intercept traffic; affected appliances should be re-imaged, credentials rotated, TOTP reset, and logs/IOCs/YARA rules reviewed to detect compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.