SonicWall SMA1000 Zero-Days Under Active Attack (CVE-2026-15409, CVE-2026-15410)
Dr. Abeer Alshammari · Published 7/29/2026
SonicWall and CISA both confirmed active exploitation. Both CVEs were added to the CISA KEV catalog on July 14, 2026, with a July 17 remediation deadline for federal agencies.
What happened
Rapid7's MDR team discovered two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances being actively exploited in the wild. SonicWall confirmed the findings and issued an urgent patch advisory. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on July 14, 2026.
Why it matters
CVE-2026-15409 is an unauthenticated server-side request forgery flaw (CVSS 10.0) -- the maximum possible severity, requiring no credentials at all. CVE-2026-15410 is a command injection vulnerability in the Appliance Management Console (CVSS 7.2) that an attacker with administrator-level access can use for arbitrary OS command execution. Chained together, these allow an unauthenticated attacker to reach deep into a supposedly hardened remote-access appliance.
Who is affected
Organizations running SonicWall SMA1000 series appliances for secure remote access / VPN functionality -- commonly internet-facing by design, which is exactly what makes this exploitable without any internal foothold.
Technical impact
| CVE | Type | CVSS | Auth required |
|---|---|---|---|
| CVE-2026-15409 | Server-side request forgery (SSRF) | 10.0 | None |
| CVE-2026-15410 | Command injection (Appliance Management Console) | 7.2 | Administrator-level |
Governance impact
Remote-access edge appliances (VPN gateways, SMA/SSL-VPN devices) have become a recurring exploitation category across the industry precisely because they must be internet-facing to function. Asset inventories should treat every edge-access appliance as a standing high-priority patch target, not a "set and forget" purchase.
What security teams should do
- Apply SonicWall's patch/mitigation to every SMA1000 appliance immediately
- Review appliance logs for indicators of compromise predating patching
- If compromise is suspected, treat any credentials or sessions handled by the appliance as potentially exposed
- Confirm SMA1000 appliances are included in your vulnerability-scanning and patch-SLA scope, not managed outside standard IT asset processes
What executives should know
This is a maximum-severity, unauthenticated flaw in an internet-facing remote-access system -- the class of device most directly exposed to attackers with no prior access. Immediate patching is the only acceptable timeline.
Edge/remote-access appliances keep reappearing in these advisories for a structural reason: they sit exactly on the boundary attackers target first. If your risk register does not separately track "internet-facing appliance patch SLA" as its own category, distinct from general server patching, this is the evidence to justify adding it.
SonicWall appliances are commonly deployed by mid-market and enterprise organizations across the GCC for branch and remote-access connectivity. Confirm SMA1000 inventory and patch status specifically, since these appliances are frequently managed separately from core IT asset lists.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon