Skip to content
SonicWall SMA1000: Attacks on partly critical zero-day vulnerabilities

SonicWall SMA1000: Attacks on partly critical zero-day vulnerabilities

Heise.De July 15, 2026

SonicWall warns of attacks on two security vulnerabilities in the SonicWall SMA1000 appliances. A hotfix is available to close the zero-day vulnerabilities. IT managers should act quickly.

In a security advisory, SonicWall writes that a Server-Side Request Forgery (SSRF) in the Work-Place Interface of the SMA1000 appliances can lead to requests being sent to areas that are actually inaccessible (CVE-2026-15409, CVSS 10.0 , Risk “ critical ”). A second vulnerability allows code injection into the Appliance Management Console (AMC) of the SMA1000. Authenticated attackers from the network can thereby execute arbitrary commands in the operating system (CVE-2026-15410, CVSS 7.2 , Risk “ high ”).

SonicWall's PSIRT has investigated several cases indicating active exploitation of these vulnerabilities, the manufacturer writes. The company therefore urgently recommends customers install the provided hotfix as soon as possible. The US IT security authority CISA has also added both vulnerabilities to the “Known Exploited Vulnerabilities” catalog , thereby confirming attacks in the wild.

According to SonicWall, the SMA1000 models 6210, 7210, and 8200v are affected if they are running firmware versions 12.4.3-03245, 12.4.3-03387, and 12.4.3-03434 or 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall does not mention temporary countermeasures; only updating to hotfix versions 12.4.3-03453 or 12.5.0-02835, respectively, or newer firmwares will help close the vulnerabilities.

Administrators can also investigate their SMA1000 appliances for signs of attack. In its security advisory, SonicWall lists some Indicators of Compromise (IOC) that attacks leave in log files, for example. If successful attacks are discovered, admins should provision the hardware with a new, clean image, change user and administrator passwords, and reset TOTP tokens.

At the end of April, SonicWall last reported relevant security vulnerabilities in SonicOS . One of them was considered high-risk.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities