Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations utilizing SonicWall SMA 1000 series appliances
Incident: Active exploitation of two zero-day vulnerabilities in SonicWall SMA 1000 series appliances.
Impact: Full system compromise via arbitrary command execution and unauthorized server-side requests.
Attacker: Unidentified threat actors
Analysis: The exploitation of CVE-2026-15409 and CVE-2026-15410 allows for severe compromise, including unauthenticated SSRF and privileged remote code execution. The inclusion of these flaws in CISA’s KEV catalog highlights the immediate risk to federal and private infrastructure. Evidence of exploitation is visible in specific system logs and configuration files.
Recommendations: Apply the latest platform-hotfix updates immediately to all SMA 1000 appliances.; Review extraweb_access.log and ctrl-service.log for suspicious API requests and path traversal.; Re-image compromised appliances and rotate all administrative credentials and TOTP tokens.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source