VORANT. Threat Intelligence Sign in Get the full feed

SonicWall SMA flaws exploited in the wild

high vulnerability

Two actively exploited SonicWall SMA 1000 vulnerabilities allow unauthenticated SSRF and authenticated remote code execution.

CERT-FR's weekly bulletin highlights a SonicWall security advisory covering two vulnerabilities in Secure Mobile Access (SMA) 1000 appliances, published July 14, 2026. CVE-2026-15409 is a critical server-side request forgery (SSRF) flaw exploitable by an unauthenticated attacker, while CVE-2026-15410 allows an authenticated administrator to achieve arbitrary remote code execution. SonicWall confirmed both vulnerabilities are being actively exploited in the wild, though it did not clarify whether an unauthenticated attacker could chain the two flaws to fully compromise a device.

SonicWall has released indicators of compromise for defenders to check against device logs. Critically, the vendor states that patching alone is insufficient if any IOC is found: affected organizations must fully reinstall the system, rotate all user and administrator passwords, and reset TOTP-based one-time password seeds. This remediation guidance suggests attackers may be achieving persistent access or credential theft on compromised appliances, elevating the urgency beyond a typical patch cycle.

Mentioned in this report

Vulnerabilities CVE-2026-15409KEVCVE-2026-15410KEV

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-031

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free