# SonicWall SMA flaws exploited in the wild

Published: 2026-07-20 · Severity: high
Canonical: https://vorant.io/reports/bbf2b447-8b27-585c-aaf8-9795850e100e/sonicwall-sma-flaws-exploited-in-the-wild

> Two actively exploited SonicWall SMA 1000 vulnerabilities allow unauthenticated SSRF and authenticated remote code execution.

CERT-FR's weekly bulletin highlights a SonicWall security advisory covering two vulnerabilities in Secure Mobile Access (SMA) 1000 appliances, published July 14, 2026. CVE-2026-15409 is a critical server-side request forgery (SSRF) flaw exploitable by an unauthenticated attacker, while CVE-2026-15410 allows an authenticated administrator to achieve arbitrary remote code execution. SonicWall confirmed both vulnerabilities are being actively exploited in the wild, though it did not clarify whether an unauthenticated attacker could chain the two flaws to fully compromise a device.

SonicWall has released indicators of compromise for defenders to check against device logs. Critically, the vendor states that patching alone is insufficient if any IOC is found: affected organizations must fully reinstall the system, rotate all user and administrator passwords, and reset TOTP-based one-time password seeds. This remediation guidance suggests attackers may be achieving persistent access or credential theft on compromised appliances, elevating the urgency beyond a typical patch cycle.

## Mentioned in this report

- Vulnerabilities: CVE-2026-15409 (KEV), CVE-2026-15410 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-031

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bbf2b447-8b27-585c-aaf8-9795850e100e/sonicwall-sma-flaws-exploited-in-the-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
