AUTO-UPDATED

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has issued urgent security patches for two actively exploited zero-day vulnerabilities in its SMA 1000 series appliances that allow attackers to execute arbitrary commands and bypass authentication.

Key Points

  • CVE-2026-15409 is a critical SSRF vulnerability with a 10.0 CVSS score, while CVE-2026-15410 is a 7.2-rated post-authentication code injection flaw.
  • Patches are available in versions 12.4.3-03453 and 12.5.0-02835 or higher to remediate the security risks.
  • CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply fixes by July 17, 2026.
  • Rapid7 reports that attackers are chaining these flaws to extract credentials and MFA seeds, enabling persistent access and lateral movement into internal networks.
  • Users should inspect logs for specific indicators of compromise and re-image appliances if unauthorized activity is detected.

Why it Matters

These vulnerabilities provide attackers with a stealthy, persistent backdoor into corporate networks by compromising perimeter security appliances. Because the flaws allow for the extraction of high-value credentials and MFA data, organizations face a significant risk of lateral movement and unauthorized access to core domain controllers.
Internet Published by info@thehackernews.com (The Hacker News)
Read original