Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. One vulnerability allows unauthenticated attackers to make requests to unintended locations, while another enables remote, authenticated attackers to execute commands as administrator. CISA has added these flaws to its KEV catalog, requiring FCEB agencies to patch them by July 17, 2026.
SonicWall has issued a critical security advisory regarding active exploitation of two zero-day vulnerabilities within its Secure Mobile Access (SMA) 1000 series appliances. These flaws are currently being leveraged by attackers, prompting a swift response from SonicWall and the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerabilities are detailed below:
- CVE-2026-15409 (CVSS score: 10.0) - A Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker could exploit this to force the appliance to make requests to unintended locations.
- CVE-2026-15410 (CVSS score: 7.2) - A post-authentication code injection vulnerability within the Appliance Management Console (AMC). A remote, authenticated attacker could execute arbitrary operating system commands as administrator under specific conditions.
SonicWall’s Product Security Incident Response Team (PSIRT), led by Adam Babis, discovered and reported the flaws, with assistance from Volexity’s Sean Koessel and Steven Adair. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by July 17, 2026. To mitigate the risk, SonicWall recommends re-imaging physical appliances or redeploying virtual appliances, changing user and administrator passwords, and resetting time-based one-time password tokens. Indicators of compromise include specific log entries, such as requests to `/__api__/login` or `/__api__/logout` with an HTTP 200 status, requests to `/wsproxy` with suspicious host parameters and a 101 HTTP status, and hotfix rollbacks with path traversal names found in `ctrl-service.log`. The presence of `/__api__/login` or `/__api__/logout` routes in `conf.json` is also a strong indicator of compromise.
