Dossier
CVE-2026-15409
Coverage of CVE-2026-15409 in the Nexus archive.
SonicWallorganization2CVE-2026-15410topic1Rapid7organization1Seth Lazarusperson1Landon Riceperson1VulnCheckorganization1Ben Harrisperson1WatchTowrorganization1Cybersecurity and Infrastructure Security Agencyorganization1Bret Fitzgeraldperson1SMA1000 appliancestopic1Secure Mobile Access (SMA) 1000 series appliancesproduct1Server-side request forgery (SSRF)topic1
- SonicWall customers under threat as attackers exploit 2 zero-days
SonicWall disclosed two zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) being exploited to compromise SMA1000 appliances, with attackers likely targeting ransomware. The vulnerabilities, chained for full system access, were first exploited on June 22, and SonicWall has released patches and mitigation tools.
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities in Secure Mobile Access (SMA) 1000 series appliances, one of which could allow arbitrary command execution. The first vulnerability, CVE-2026-15409, is a server-side request forgery (SSRF) flaw exploitable by unauthenticated attackers.