SonicWall Warns of Actively Exploited Zero-Day Vulnerabilities in SMA 1000 Appliances

SonicWall has issued an urgent advisory warning that two zero-day vulnerabilities affecting its Secure Mobile Access 1000 series appliances are being actively exploited in the wild. One of the flaws could allow unauthenticated attackers to achieve arbitrary command execution.

The vulnerabilities include CVE-2026-15409, a server-side request forgery vulnerability with a CVSS score of 10.0 that permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost services. The second flaw, CVE-2026-15410, is a local privilege escalation that could allow an attacker with access to internal services to execute arbitrary operating system commands as root.

Rapid7’s Managed Detection and Response team discovered the vulnerabilities after observing active, targeted zero-day exploitation of internet-facing SMA 1000 appliances. Both flaws have been added to CISA’s Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by an expedited deadline.

The affected models include SonicWall SMA 1000 Series 6210, 7210, and 8200v running specific firmware versions. SonicWall has released hotfixes to address the vulnerabilities and is urging customers to apply them immediately on an emergency basis.

The vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line, limiting the scope of impacted devices to the SMA 1000 series remote access appliances.

Security experts recommend that organizations using the affected appliances prioritize patching given the confirmed active exploitation and the critical severity of the vulnerabilities.

References

This article was adapted from Rapid7. Read the original here.