SonicWall SMA1000 flaws under active exploitation
SonicWall confirms active exploitation of two SMA1000 vulnerabilities enabling remote code execution and SSRF.
ANSSI-CERT-FR has issued an advisory regarding multiple vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances, affecting models 6210, 7210, and 8200v. The flaws allow attackers to achieve remote code execution and server-side request forgery (SSRF) against affected devices running versions prior to 12.5.0-02835 (12.5.x branch) or prior to 12.4.3-03453.
SonicWall's own security bulletin (SNWLID-2026-0008) confirms that two of the identified vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited in the wild. Given SMA1000 devices are typically internet-facing remote access gateways, active exploitation of RCE-capable flaws poses a significant risk to organizations that have not yet applied patches. Affected organizations should prioritize patching per SonicWall's guidance.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0875
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free