SonicWall confirms that two vulnerabilities in its SMA 1000 appliances are being exploited right now, and on 14 July CISA added them to its exploited-vulnerabilities catalog.
The first, CVE-2026-15409, carries the maximum severity score (CVSS 10.0): an unauthenticated attacker can force the appliance to send requests to unwanted destinations. The second, CVE-2026-15410, allows command execution as administrator. Affected: SMA1000 models 6210, 7210 and 8200v.
- Check whether you have a SonicWall SMA at the network edge — usually the box your team uses to connect from home.
- If so, apply hotfix 12.4.3-03453 or 12.5.0-02835.
- Review VPN access logs from the past two weeks.
Sources
This article was generated with AI assistance.