SonicWall has patched two vulnerabilities that are being actively exploited against SMA 1000 Series appliances, affecting models including 6210, 7210, and 8200v. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, impact multiple 12.4.3 and 12.5.0 platform-hotfix releases. SonicWall described CVE-2026-15409 as a critical unauthenticated SSRF issue in the Appliance Work Place interface and CVE-2026-15410 as a high-severity code injection flaw in the Appliance Management Console that can allow an authenticated administrator to execute arbitrary operating system commands. SonicWall said the vulnerabilities have been exploited together in the wild and released hotfixes to address them.
Government and vendor advisories urged organizations to update immediately and investigate appliances for signs of compromise, warning that patching alone may not be sufficient if an appliance has already been breached. SonicWall recommended reviewing logs, re-imaging or re-deploying affected systems where indicators are found, changing user and administrator passwords, and resetting TOTP tokens. The Canadian Centre for Cyber Security highlighted the advisory, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog the same day, underscoring the urgency for defenders to remediate exposed SMA1000 deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On July 17, 2026, Volexity reported that threat actor UTA0533 exploited a chain of SonicWall SMA1000 zero-days to gain root access on 6210, 7210, and 8200v appliances. The report disclosed post-compromise tradecraft including malware Volexity named ROOTRUN, KNUCKLEBALL, and ORANGETAIL, nginx routing changes for covert webshell access, and use of Suo5 and tcpdump.
Rapid7 reported that threat actors associated with the Inc ransomware group exploited CVE-2026-15409 and CVE-2026-15410 on SonicWall SMA1000 appliances for initial access, credential theft, session harvesting, and lateral movement toward domain controllers. The report said the activity led to successful ransomware deployment in at least one case.
A GitHub pull request to the Metasploit Framework introduced an exploit module for the SonicWall SMA1000 WorkPlace wsproxy SSRF flaw CVE-2026-15409. The module documentation and example usage indicated remote exploitation and command-execution capability against vulnerable targets.
Before SonicWall publicly disclosed the flaws, Rapid7's MDR team observed targeted exploitation of internet-facing SMA1000 appliances using CVE-2026-15409 and CVE-2026-15410. According to Rapid7, attackers chained the bugs to access localhost-only services, gain code execution and root privileges, harvest credentials and TOTP seeds, and pivot into internal Active Directory environments.
On July 14, 2026, CISA added CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities catalog. The addition reflected reporting that both flaws were being actively exploited in the wild.
On July 14, 2026, SonicWall's advisory included indicators of compromise for SMA1000 appliances and warned that patching alone is insufficient if those indicators are present in logs. The company recommended reinstalling affected systems, changing all user and administrator passwords, and resetting TOTP secrets in suspected compromises.
On July 14, 2026, SonicWall published a security advisory for actively exploited SMA1000 Series vulnerabilities CVE-2026-15409 and CVE-2026-15410, affecting models 6210, 7210, and 8200v. The company released hotfixes and urged customers to upgrade immediately and investigate appliances for signs of compromise.
Third-party researchers said attackers were exploiting the SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 as early as June 22, 2026. The report places active exploitation weeks before SonicWall's public disclosure and patch release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
43 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocradar.io
Open sourcehelpnetsecurity.com
Open sourcesecurityweek.com
Open sourcecisa.gov
Open sourcecodeby.net
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.