Two SonicWall SMA 1000 flaws under active exploitation

SonicWall confirms that two vulnerabilities in its SMA 1000 appliances are being exploited right now, and on 14 July CISA added them to its exploited-vulnerabilities catalog.

The first, CVE-2026-15409, carries the maximum severity score (CVSS 10.0): an unauthenticated attacker can force the appliance to send requests to unwanted destinations. The second, CVE-2026-15410, allows command execution as administrator. Affected: SMA1000 models 6210, 7210 and 8200v.

  • Check whether you have a SonicWall SMA at the network edge — usually the box your team uses to connect from home.
  • If so, apply hotfix 12.4.3-03453 or 12.5.0-02835.
  • Review VPN access logs from the past two weeks.

Sources

This article was generated with AI assistance.

Have your perimeter gear checked

← All news