Zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 may enable compromise of SonicWall SMA1000 appliances
Zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 may enable compromise of SonicWall SMA1000 appliances
The following platforms are known to be affected:
SonicWall Secure Mobile Access (SMA) 1000 Series
Models 6210, 7210 and 8200v running:
Exploitation of CVE-2026-15409 and CVE-2026-15410
SonicWall has stated that it has investigated multiple cases indicating the active exploitation of these vulnerabilities. SonicWall strongly urge customers to update to the relevant hotfix release as soon as possible to remediate these vulnerabilities.
Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance , including patching edge devices as soon as possible if a critical vulnerability is identified.
The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain.
SonicWall has released a security advisory to address zero-day vulnerabilities in the SMA1000 Appliance Work Place interface and SMA1000 Appliance Management Console (AMC).
Note : These vulnerabilities do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.
Affected organisations must review SonicWall's security advisory SNWLID-2026-0008 and apply the relevant updates as soon as possible. Additional recommended remediation steps below outline how to determine if an appliance has been compromised.
If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected] .
Required: Organisations should patch to a fixed version:
Strongly Recommended: Monitor for indicators of compromise (IoCs) on affected SMA1000 appliances.
In extraweb_access.log , check for requests to:
In extraweb_access.log , check for requests to:
with suspicious host parameters and HTTP 101 status codes.
In ctrl-service.log , look for hotfix rollbacks that include path traversal-style names.
Check /var/lib/unit/conf.json for routes to:
These routes are not present in legitimate configurations.
If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected] .
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Last edited: 15 July 2026 11:32 am
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
