← Back to blog

SonicWall SMA 1000 Zero-Days Under Active Attack

Two critical zero-day flaws in SonicWall's Secure Mobile Access appliances are being actively exploited. One allows full admin command execution without authentication.

TL;DR

  • SonicWall warns of two zero-day vulnerabilities in SMA 1000 series devices
  • CVE-2026-15409 (CVSS 10.0) enables SSRF leading to arbitrary command execution
  • Both flaws can be exploited remotely without authentication
  • Attackers are actively exploiting these vulnerabilities in the wild
  • Organizations should immediately apply available patches or implement mitigations

SonicWall has issued an urgent security advisory regarding two zero-day vulnerabilities affecting their Secure Mobile Access (SMA) 1000 series appliances. These critical flaws are currently being exploited in real-world attacks, putting organizations at immediate risk of unauthorized access and system compromise.

The most severe of the two vulnerabilities carries a maximum CVSS score of 10.0, indicating critical severity. Both flaws can be exploited remotely by unauthenticated attackers, making them particularly dangerous for exposed network infrastructure.

Critical Vulnerability Details

  • CVE-2026-15409 is a server-side request forgery (SSRF) flaw with maximum CVSS score of 10.0
  • The SSRF vulnerability allows remote attackers to execute arbitrary administrative commands
  • No authentication is required to exploit either vulnerability
  • Successful exploitation could lead to complete device compromise and network access
  • Affected devices include SonicWall SMA 1000 series secure mobile access appliances

Immediate Response Actions

  • Organizations should immediately audit their exposure to SonicWall SMA 1000 devices
  • Apply vendor-released patches as soon as possible for affected systems
  • Implement network segmentation to limit access to vulnerable appliances
  • Monitor network logs for suspicious activity indicative of these exploits
  • Consider temporary offline measures for unpatchable critical systems

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

SonicWall SMA 1000 Zero-Days Under Active Attack — Agent Breach Blog | Agent Breach