Two SonicWall SMA 1000 vulnerabilities, actively exploited and added to the CISA KEV

SonicWall confirms that two vulnerabilities in SMA 1000 devices are currently being exploited, and CISA added them to its list of actively exploited vulnerabilities on July 14. For companies that allow their employees to access the network from home using this type of equipment, this is an issue that needs to be addressed today—not during the next maintenance window.

The first vulnerability, CVE-2026-15409, has a maximum severity score (CVSS 10.0): an unauthenticated attacker—without an account or password—can force the device to send requests to unwanted destinations. The second, CVE-2026-15410, allows for the execution of commands as an administrator. Affected models include the SMA1000 6210, 7210, and 8200v.

The difference from a typical alert is that, in this case, the vendor confirms that the vulnerability is being exploited in real-world attacks, and its inclusion in the CISA catalog means that we are no longer dealing with a theoretical risk. Specific steps for a small business:

  • Check to see if you have a SonicWall SMA at the network edge. It's usually the device that your coworkers use to access the company network from home.
  • If so, apply hotfix 12.4.3-03453 or 12.5.0-02835.
  • Review the VPN access logs from the past two weeks to see if there were any unusual connections.

The VPN equipment is the company's front door. When the manufacturer confirms that it has been compromised, it's no longer just a routine update. If you’re not sure what equipment is at the edge of your network or who keeps it up to date, you can email us at [email protected] or call us at +40 712 605 222.

Source: The Hacker News / CISA KEV | https://thehackernews.com/2026/07/two-sonicwall-sma-1000-zero-days.html

This article was generated with AI assistance.

Request a quote

← All news