SonicWall Announces Exploitation of Two Zero‑Day Vulnerabilities in Secure Mobile Access Appliances
Apply SonicWall patches for CVE‑2026‑15409 and CVE‑2026‑15410 to eliminate SSRF and arbitrary command execution.
Apply the SonicWall security patches for CVE‑2026‑15409 and CVE‑2026‑15410 immediately.
Summary
SonicWall has warned of active exploitation of two zero‑day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances. CVE‑2026‑15409 is a server‑side request forgery (SSRF) that allows a remote unauthenticated attacker to request arbitrary URLs, potentially leading to data exfiltration. CVE‑2026‑15410 enables arbitrary command execution, giving attackers full control over the device. Both vulnerabilities have CVSS scores of 10.0 and 9.8 respectively, and are currently being exploited in the wild. SonicWall has released patches that mitigate the SSRF and command‑execution flaws. The patches update the request handling logic and enforce strict authentication checks. Users are urged to apply the updates immediately to prevent device takeover. The incident underscores the importance of timely patching for network security appliances.
Key changes
- CVE‑2026‑15409 SSRF allows remote unauthenticated attacker to request arbitrary URLs
- CVE‑2026‑15410 allows arbitrary command execution on SMA 1000 series appliances
- Both vulnerabilities have CVSS scores of 10.0 and 9.8
- Active exploitation reported in the wild
- SonicWall released patches that mitigate SSRF and command‑execution flaws
- Patches update request handling logic and enforce strict authentication checks