# SonicWall SMA1000 flaws under active exploitation

Published: 2026-07-15 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/eb74b1c6-5aee-5e21-9f0e-2dbc045de514/sonicwall-sma1000-flaws-under-active-exploitation

> SonicWall confirms active exploitation of two SMA1000 vulnerabilities enabling remote code execution and SSRF.

ANSSI-CERT-FR has issued an advisory regarding multiple vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances, affecting models 6210, 7210, and 8200v. The flaws allow attackers to achieve remote code execution and server-side request forgery (SSRF) against affected devices running versions prior to 12.5.0-02835 (12.5.x branch) or prior to 12.4.3-03453.

SonicWall's own security bulletin (SNWLID-2026-0008) confirms that two of the identified vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited in the wild. Given SMA1000 devices are typically internet-facing remote access gateways, active exploitation of RCE-capable flaws poses a significant risk to organizations that have not yet applied patches. Affected organizations should prioritize patching per SonicWall's guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2026-15409 (KEV), CVE-2026-15410 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0875

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/eb74b1c6-5aee-5e21-9f0e-2dbc045de514/sonicwall-sma1000-flaws-under-active-exploitation.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
