logo

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

ID: 200ac825-9704-5502-8478-89329da358a2

STIX ID: report--200ac825-9704-5502-8478-89329da358a2

Feed Name: The Hacker News

Threat Score
92/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

**SonicWall SMA 1000 zero-days under active exploitation:** SonicWall disclosed two zero-day vulnerabilities—CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-auth code injection, CVSS 7.2)—being actively exploited against SMA appliances; patches are available in 12.4.3-03453 (platform-hotfix) and higher and 12.5.0-02835 (platform-hotfix) and higher, CISA added both to its KEV list requiring fixes by July 17, 2026, and SonicWall published IoCs and recommended forensic steps (including re-imaging if indicators are found).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.