CVE Tools

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)

Help Net SecurityBy Zeljka Zorz

Reported exploitedSecure Mobile Access (SMA) 1000 Series appliances

Our summary

SonicWall has addressed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) impacting its Secure Mobile Access (SMA) 1000 Series appliances. These flaws were being used together in real-world attacks, allowing unauthenticated attackers to trigger SSRF and authenticated users to execute arbitrary code. Customers are advised to apply the latest firmware updates and check for signs of compromise. SonicWall also recommends additional post-patch actions like password resets and TOTP token regeneration.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store