**Critical SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now**
SonicWall has issued a dire warning about two critical vulnerabilities affecting its SMA1000 appliances, which have been exploited in zero-day attacks. The company is urging customers to install the newly released security updates as soon as possible to prevent further damage.
The two vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, are being actively exploited by threat actors, according to SonicWall. CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability that allows an unauthenticated attacker to force the appliance to make requests to unintended locations. This flaw has been assigned a critical severity rating of CVSS 10.0. Meanwhile, CVE-2026-15410 is a post-authentication code injection vulnerability that could allow a remote authenticated administrator to execute arbitrary operating system commands.
Despite requiring administrator privileges for exploitation, SonicWall’s overall CVSS score for this vulnerability is also 10.0, highlighting the significant risk posed by these flaws. SonicWall has confirmed multiple incidents of active exploitation and is urging customers to upgrade to the latest hotfix release as soon as possible.
The affected SMA1000 models are those running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.
SonicWall has also shared indicators of compromise (IOCs) that administrators can use to determine whether an appliance has been compromised. These include suspicious requests to the /__api__/login or /__api__/logout URLs in the extraweb_access.log file, as well as hotfix rollbacks with path traversal names in the ctrl-service.log file.
If a device is found to be compromised, SonicWall advises administrators to re-image physical appliances or redeploy virtual appliances, change all user and administrator passwords, and reset TOTP tokens. Unfortunately, there are no workarounds or mitigations for these flaws other than installing the hotfixes.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are being actively exploited in attacks. Federal agencies have until July 17, 2026, to secure affected systems under Binding Operational Directive (BOD) 26-04 or discontinue use of the product if mitigations cannot be applied.
In light of these critical vulnerabilities and their active exploitation, it’s essential for security teams to prioritize patching and testing their systems. This incident serves as a reminder that zero-day attacks can happen at any time, and being prepared is crucial in preventing damage.
Source: Bleeping Computer — 2026-07-14