Forum Discussion
CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
On July 14, SonicWall disclosed two vulnerabilities that are being exploited together in the wild:
|
CVE |
Description |
CVSSv3 |
|
CVE-2026-15409 |
SonicWall SMA 1000 server-side request forgery (SSRF) vulnerability |
10 |
|
CVE-2026-15410 |
SonicWall SMA 1000 remote code execution vulnerability (RCE) |
7.2 |
While the advisory does not specify if they were exploited in tandem, together they form a fully remote, unauthenticated path to arbitrary OS command execution on affected appliances.
CVE-2026-15409 is a SSRF vulnerability affecting the SMA 1000 Workplace interface. This flaw allows a remote, unauthenticated attacker to make network requests to locations of the attacker's choosing. In practice, SSRF on an internet-facing appliance can serve as a pivot, allowing an attacker to probe internal services, relay authentication material, or reach the AMC in a way that bypasses normal access controls.
CVE-2026-15410 is a code injection vulnerability in the Appliance Management Console (AMC). The AMC is the administrative interface used to configure the appliance, manage users, set access policies, and monitor sessions. While this flaw does require the user to be authenticated, the potential chaining of these vulnerabilities makes the exploitation path possible without authentication
These flaws have been exploited in the wild as zero-days. While SonicWall has not provided any details on attribution of which threat actors may be behind the attacks, several SonicWall vulnerabilities have been targeted in the past, including the exploitation of zero-days.
For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.