CVE Tools

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

BleepingComputerBy Lawrence Abrams

Reported exploitedSMA1000 Appliance

Our summary

SonicWall has issued a warning that two critical vulnerabilities in its SMA1000 Appliance are currently being exploited in real-world attacks. The flaws, identified as CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), enable remote attackers to perform server-side request forgery and execute arbitrary commands after authentication. These issues affect specific SMA1000 models running outdated firmware versions. SonicWall urges users to apply the latest hotfixes immediately to prevent potential breaches. CISA has also listed these vulnerabilities in its KEV catalog due to their active exploitation.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store