CVE Tools

SonicWall SMA zero-days were exploited weeks before disclosure

Help Net SecurityBy Zeljka Zorz

Reported exploitedSecure Mobile Access (SMA) 1000 Series

Our summary

Researchers from Volexity have confirmed that two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 devices—CVE-2026-15409 and CVE-2026-15410—were actively exploited as zero-day flaws weeks before being publicly disclosed. These exploits enabled attackers to gain unauthorized access, install custom malware, and maintain persistent control over vulnerable systems. The attacks started as early as June 22, 2026, with threat actors leveraging these flaws to bypass security controls and exfiltrate sensitive data. SonicWall has issued patches, but experts warn that patching alone is insufficient; organizations must also check for signs of compromise and reset credentials.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store