OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CVE-2026-15410. The advisory urges customers to immediately apply the latest platform hotfix releases.Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based remove_hotfix workflow.Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was noted, and both CVE-2026-15409 and CVE-2026-15410 have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis.Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:12.4.3-0324512.4.3-0338712.4.3-03434 (platform-hotfix)12.5.0-0228312.5.0-0262412.5.0-02800 (platform-hotfix)These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.Technical overviewThe primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arb According to Rapid7 Blog, overviewon july 14, 2026, sonicwall published a security advisory addressing two vulnerabilities affecting sma1000 series remote access appliances, including the critical server-side request forgery (ssrf) vulnerability cve-2026-15409 (cvss 10.0) and the high-severity code injection vulnerability cve-2026-15410. the advisory urges customers to immediately apply the latest platform hotfix releases.successful exploitation of cve-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while cve-2026-15410 is a local privilege escalation that permits an attacker with access to an internal…
