SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
The vulnerabilities are listed below –
CVE-2026-15409 (CVSS score: 10.0) – A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to According to The Hacker News, sonicwall has warned of active exploitation of two zero-day vulnerabilities impacting secure mobile access (sma) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
the vulnerabilities are listed below –
cve-2026-15409 (cvss score: 10.0) – a server-side request forgery (ssrf) vulnerability that a remote unauthenticated attacker could exploit to. The development comes amid ongoing regulatory scrutiny in the sector. The Hacker News reports that this marks a significant milestone for the industry. The The Hacker News report provides additional context on the implications for market participants and regulatory frameworks moving forward.
