VORANT. Threat Intelligence Sign in Get the full feed

SonicWall SMA 1000 flaws exploited in wild

high vulnerability

Two SonicWall SMA 1000 vulnerabilities, including an unauthenticated SSRF, are being actively exploited to compromise devices.

SonicWall disclosed two vulnerabilities affecting its SMA 1000 series Secure Mobile Access appliances (models 6210, 7210, and 8200v) on July 14, 2026. CVE-2026-15409 is a critical unauthenticated server-side request forgery (SSRF) flaw, while CVE-2026-15410 allows an authenticated administrator to achieve remote code execution. SonicWall confirmed both vulnerabilities are being actively exploited in the wild, though it has not clarified whether an unauthenticated attacker could chain the two flaws to gain full control of an affected device.

SonicWall has published indicators of compromise for defenders to search their logs. Critically, the vendor states that if any of these indicators are found, simply applying the patch is insufficient — affected organizations must fully reinstall the system, rotate all user and administrator passwords, and reset TOTP-based one-time password seeds. The French CERT-FR has issued an alert directing organizations to SonicWall's advisory (SNWLID-2026-0008) for patches and remediation guidance.

Given the active exploitation of an unauthenticated SSRF vulnerability in an internet-facing remote access product, affected organizations should treat this as an urgent patching and compromise-assessment priority, following the vendor's full remediation steps rather than patching alone.

Mentioned in this report

Vulnerabilities CVE-2026-15409KEVCVE-2026-15410KEV

Source reporting: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-006

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free