SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
SonicWall has issued an urgent patch warning due to two newly exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances. Threat actors are actively leveraging these flaws, and CISA has added them to its list of known exploited vulnerabilities, requiring immediate action from organizations using affected devices.
SonicWall is urging customers to immediately update their SMA1000 secure remote access appliances to address two critical zero-day vulnerabilities. These vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, are being actively exploited by threat actors. CVE-2026-15409 is a critical server-side request forgery (SSRF) issue affecting the Appliance Work Place interface, allowing unauthenticated attackers to make requests to unintended locations. CVE-2026-15410 is a high-severity code injection issue affecting the Appliance Management Console (AMC), enabling attackers with admin privileges to execute arbitrary OS commands. SonicWall PSIRT has investigated multiple cases indicating active exploitation of these vulnerabilities. Volexity assisted in SonicWall’s investigation, but details are still limited. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging government agencies to address them by July 17. The vendor has shared Indicators of Compromise (IoCs) to assist in detection efforts. This situation highlights a common trend of threat actors targeting SonicWall products for exploitation.