Two SonicWall SMA1000 flaws are being actively exploited in zero-day attacks. SonicWall has released emergency security updates and is urging customers to install them immediately.
The vulnerabilities affect several SMA1000 models and can allow attackers to redirect server requests or run operating system commands.
Critical SSRF Flaw Receives Maximum Severity Score
The first vulnerability, tracked as CVE-2026-15409, affects the SMA1000 Appliance Work Place interface.
It is a critical server-side request forgery flaw with a CVSS score of 10.0.
A remote attacker does not need to log in to exploit the issue. Instead, they can force a vulnerable appliance to send requests to unintended internal or external locations.
As a result, attackers may gain access to systems or services that should not be exposed.
Code Injection Flaw Requires Administrator Access
The second vulnerability, CVE-2026-15410, affects the SMA1000 Appliance Management Console.
It is a high-severity code injection flaw with a CVSS score of 7.2.
An attacker must already have authenticated administrator access. However, successful exploitation could allow them to execute arbitrary commands on the operating system.
Although this flaw has a lower individual score, SonicWall gave the overall security advisory a maximum severity rating.
SonicWall Confirms Active Exploitation
SonicWall investigated several incidents and confirmed that attackers are actively exploiting both vulnerabilities.
However, the company has not said whether threat actors are combining the two flaws in the same attack chain.
SonicWall is strongly advising customers to install the latest hotfix versions as soon as possible.
Affected SMA1000 Models and Versions
The SonicWall SMA1000 flaws affect the following models:
- SMA 6210
- SMA 7210
- SMA 8200v
Several platform-hotfix releases in the 12.4.3 and 12.5.0 branches are vulnerable.
Fixes are available in:
- Platform-hotfix 12.4.3-03453
- Platform-hotfix 12.5.0-02835
- All later supported versions
SonicWall says the flaws do not affect SSL-VPN services running on its firewalls. They also do not affect the SMA 100 Series.
Indicators of Compromise Shared
SonicWall published several indicators that may reveal whether an SMA1000 appliance has already been compromised.
Administrators should check for:
- Requests to
/__api__/loginor/__api__/logoutreturning HTTP 200 inextraweb_access.log - Requests to
/wsproxywith suspicious host parameters and HTTP 101 responses - Hotfix rollback entries containing path traversal names in
ctrl-service.log - Unexpected routes for
/__api__/loginor/__api__/logoutinside/var/lib/unit/conf.json
Those API routes should not appear in a legitimate configuration.
Compromised Appliances Must Be Rebuilt
Installing the hotfix is not enough if attackers have already gained access.
SonicWall recommends re-imaging compromised physical appliances. Virtual appliances should be completely redeployed.
Administrators should also:
- Change every user and administrator password
- Reset all time-based one-time password tokens
- Review logs for suspicious activity
- Check connected systems for further signs of compromise
The company says no workaround or temporary mitigation is available. Therefore, installing the security updates is the only way to protect vulnerable systems.
CISA Adds Flaws to Exploited Vulnerability Catalog
The U.S. Cybersecurity and Infrastructure Security Agency has added both vulnerabilities to its Known Exploited Vulnerabilities catalog.
This confirms that attackers are using the flaws in real-world incidents.
Federal agencies must secure affected systems by July 17, 2026. If they cannot apply the updates, they must stop using the affected products.
Organizations running vulnerable SMA1000 appliances should patch immediately and investigate for signs of previous exploitation.


0 responses to “SonicWall SMA1000 Flaws Exploited in Zero-Day Attacks”