Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
ID: 200ac825-9704-5502-8478-89329da358a2
STIX ID: report--200ac825-9704-5502-8478-89329da358a2
Feed Name: The Hacker News
**SonicWall SMA 1000 zero-days under active exploitation:** SonicWall disclosed two zero-day vulnerabilities—CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-auth code injection, CVSS 7.2)—being actively exploited against SMA appliances; patches are available in 12.4.3-03453 (platform-hotfix) and higher and 12.5.0-02835 (platform-hotfix) and higher, CISA added both to its KEV list requiring fixes by July 17, 2026, and SonicWall published IoCs and recommended forensic steps (including re-imaging if indicators are found).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
