Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

July 15, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations utilizing SonicWall SMA 1000 series appliances
Incident: Active exploitation of two zero-day vulnerabilities in SonicWall SMA 1000 series appliances.
Impact: Full system compromise via arbitrary command execution and unauthorized server-side requests.
Attacker: Unidentified threat actors
Analysis: The exploitation of CVE-2026-15409 and CVE-2026-15410 allows for severe compromise, including unauthenticated SSRF and privileged remote code execution. The inclusion of these flaws in CISA’s KEV catalog highlights the immediate risk to federal and private infrastructure. Evidence of exploitation is visible in specific system logs and configuration files.
Recommendations: Apply the latest platform-hotfix updates immediately to all SMA 1000 appliances.; Review extraweb_access.log and ctrl-service.log for suspicious API requests and path traversal.; Re-image compromised appliances and rotate all administrative credentials and TOTP tokens.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *