SonicWall SMA zero-days were exploited weeks before disclosure
Reported exploitedSecure Mobile Access (SMA) 1000 SeriesOur summary
Researchers from Volexity have confirmed that two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 devices—CVE-2026-15409 and CVE-2026-15410—were actively exploited as zero-day flaws weeks before being publicly disclosed. These exploits enabled attackers to gain unauthorized access, install custom malware, and maintain persistent control over vulnerable systems. The attacks started as early as June 22, 2026, with threat actors leveraging these flaws to bypass security controls and exfiltrate sensitive data. SonicWall has issued patches, but experts warn that patching alone is insufficient; organizations must also check for signs of compromise and reset credentials.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.