bleeping-computer · Crawled Jul 14, 2026
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
3 IoCs
Read original article ↗
AI Summary
SonicWall has warned of active zero-day exploitation of two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in its SMA1000 appliances. CVE-2026-15409 is a critical SSRF flaw allowing unauthenticated remote attackers to force unintended requests, while CVE-2026-15410 is a post-authentication code injection vulnerability enabling arbitrary command execution. Both vulnerabilities are being actively exploited, with an overall CVSS score of 10.0, and affect multiple SMA1000 models. Immediate patching is advised, as no mitigations exist beyond updating to the latest hotfix releases.
AI-extracted · verify before operational use