SonicWall has issued urgent security patches for two actively exploited zero-day vulnerabilities in its SMA 1000 series appliances that allow attackers to execute arbitrary commands and bypass authentication.
Key Points
- CVE-2026-15409 is a critical SSRF vulnerability with a 10.0 CVSS score, while CVE-2026-15410 is a 7.2-rated post-authentication code injection flaw.
- Patches are available in versions 12.4.3-03453 and 12.5.0-02835 or higher to remediate the security risks.
- CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply fixes by July 17, 2026.
- Rapid7 reports that attackers are chaining these flaws to extract credentials and MFA seeds, enabling persistent access and lateral movement into internal networks.
- Users should inspect logs for specific indicators of compromise and re-image appliances if unauthorized activity is detected.