CVE Tools

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)

Rapid7 BlogBy Rapid77 min read

Reported exploitedSMA1000 Series

Our summary

Two zero-day vulnerabilities in SonicWall SMA1000 Series devices—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410—are currently being actively exploited in attacks. The flaws allow unauthenticated attackers to create tunnels to internal services and escalate privileges to root. Rapid7’s MDR team detected real-world exploitation before official disclosure. Both issues are now listed in CISA’s KEV catalog. Affected versions include multiple firmware builds of models 6210, 7210, and 8200v. SonicWall has issued patches; users are urged to update immediately to prevent compromise.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409">CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CVE-2026-15410">CVE-2026-15410. The advisory urges customers to immediately apply the latest platform hotfix releases.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store