SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments.
What is the threat?
CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability in the SMA1000 Workplace interface that allows an unauthenticated attacker to force the appliance to make outbound requests. This could expose internal services, cloud metadata endpoints, and other resources not directly accessible from the internet.
CVE-2026-15410 is a post-authentication code injection vulnerability in the Management Console that allows an authenticated administrator to execute operating system commands on the device.
An attacker could potentially chain these vulnerabilities, using SSRF to access internal resources and code injection to gain full control of the appliance.
Why is it noteworthy?
These vulnerabilities are actively exploited and affect remote access infrastructure, making them a high-priority risk.
CVE-2026-15409 is unauthenticated and carries a CVSS score of 10.0, while CVE-2026-15410 enables command execution after authentication. Together, they can lead to full device compromise.
CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. SonicWall states there are no mitigations beyond patching.
What is the exposure or risk?
Affected systems include SMA1000 models 6210, 7210, and 8200v running the following versions:
- 12.4.3-03245
- 12.4.3-03387
- 12.4.3-03434
- 12.5.0-02283
- 12.5.0-02624
- 12.5.0-02800
SSL-VPN on SonicWall firewalls and SMA 100 Series appliances are not affected.
Successful exploitation could allow attackers to access internal resources, execute commands on the appliance, steal credentials, exfiltrate data, move laterally through the environment, or cause service disruption. Risk increases when management interfaces are exposed to the internet, administrative access is broadly granted, or monitoring is limited.
What are the recommendations?
Barracuda recommends the following actions to mitigate risk:
- Patch immediately to 12.4.3-03453, 12.5.0-02835, or later.
- Review SonicWall’s indicators of compromise (IOCs), including suspicious
/api/loginand/api/logoutactivity, anomalous/wsproxyhost parameters, hotfix rollbacks involving path traversal, and unexpected routes inconf.json. - Treat any IOC findings as a potential breach.
- Re-image or re-deploy the appliance if compromise is suspected. Reset all user and administrator passwords and rotate TOTP tokens.
- Restrict management access to trusted networks or VPNs, enforce MFA, and increase logging and monitoring.
References
For more in-depth information about the recommendations, please visit the following links:
- https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ
- https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-15409
- https://nvd.nist.gov/vuln/detail/CVE-2026-15410
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.

