logo

CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation

ID: c142786f-6a9e-586e-b173-c983ead4f893

STIX ID: report--c142786f-6a9e-586e-b173-c983ead4f893

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Ashish Khaitan

...
...

**Executive summary:** SonicWall SMA1000 Series appliances are affected by two critical vulnerabilities—CVE-2026-15409 (unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (post-authentication code injection, CVSS 7.2)—that are being actively exploited in the wild; SonicWall and CISA recommend immediate upgrade to hotfix releases (12.4.3-03453+ and 12.5.0-02835+) and provide IOCs and remediation steps including log inspection, re-imaging/redeployment, credential resets, and TOTP token resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.