Share This:

Cybersecurity Threat AdvisorySonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments.

What is the threat?

CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability in the SMA1000 Workplace interface that allows an unauthenticated attacker to force the appliance to make outbound requests. This could expose internal services, cloud metadata endpoints, and other resources not directly accessible from the internet.

CVE-2026-15410 is a post-authentication code injection vulnerability in the Management Console that allows an authenticated administrator to execute operating system commands on the device.

An attacker could potentially chain these vulnerabilities, using SSRF to access internal resources and code injection to gain full control of the appliance.

Why is it noteworthy?

These vulnerabilities are actively exploited and affect remote access infrastructure, making them a high-priority risk.

CVE-2026-15409 is unauthenticated and carries a CVSS score of 10.0, while CVE-2026-15410 enables command execution after authentication. Together, they can lead to full device compromise.

CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. SonicWall states there are no mitigations beyond patching.

What is the exposure or risk?

Affected systems include SMA1000 models 6210, 7210, and 8200v running the following versions:

  • 12.4.3-03245
  • 12.4.3-03387
  • 12.4.3-03434
  • 12.5.0-02283
  • 12.5.0-02624
  • 12.5.0-02800

SSL-VPN on SonicWall firewalls and SMA 100 Series appliances are not affected.

Successful exploitation could allow attackers to access internal resources, execute commands on the appliance, steal credentials, exfiltrate data, move laterally through the environment, or cause service disruption. Risk increases when management interfaces are exposed to the internet, administrative access is broadly granted, or monitoring is limited.

What are the recommendations?

Barracuda recommends the following actions to mitigate risk:

  • Patch immediately to 12.4.3-03453, 12.5.0-02835, or later.
  • Review SonicWall’s indicators of compromise (IOCs), including suspicious /api/login and /api/logout activity, anomalous /wsproxy host parameters, hotfix rollbacks involving path traversal, and unexpected routes in conf.json.
  • Treat any IOC findings as a potential breach.
  • Re-image or re-deploy the appliance if compromise is suspected. Reset all user and administrator passwords and rotate TOTP tokens.
  • Restrict management access to trusted networks or VPNs, enforce MFA, and increase logging and monitoring.

References

For more in-depth information about the recommendations, please visit the following links:

If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.


Share This:
Leavar Michel

Posted by Leavar Michel

Leavar is a Cybersecurity Analyst at Barracuda. He's a security expert, working on our Blue Team within our Security Operations Center. Leavar supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.