Arctic Wolf Security Bulletin
Arctic Wolf Security Bulletin

CVE-2026-15409, CVE-2026-15410: Security Bulletin: SonicWall SMA 1000 Series Zero-Day Vulnerabilities

SonicWall SMA1000 critical SSRF + code injection vulnerabilities (CVE-2026-15409/15410) exploited in the wild. Full device compromise risk. Immediate patching required.
Arctic Wolf Security Bulletin
6 min read

Threat Summary

Two severe vulnerabilities affecting SonicWall Secure Mobile Access 1000 (SMA1000) series appliances have been confirmed as under active exploitation since their public disclosure on July 14, 2026.

CVE-2026-15409 is a critical server-side request forgery (SSRF) vulnerability (CVSS 10.0) in the SMA1000 “Work Place” interface, allowing remote, unauthenticated attackers to coerce appliances into sending requests to arbitrary internal or external destinations. This can be used as an entry point for lateral movement or chaining with other exploits. CVE-2026-15410 is a high-severity post-authentication code injection flaw (CVSS 7.2), allowing authenticated admin users to execute arbitrary OS-level commands via the management console.

Attacks observed in the wild combine both flaws to achieve full remote compromise and persistence on affected appliances.

Affected models include SMA 6210, 7210, and 8200v running platform-hotfix firmware versions 12.4.3‑03245, -03387, -03434, 12.5.0‑02283, -02624, and -02800. Exploited vulnerabilities have prompted rapid vendor and government action. SonicWall issued emergency advisories and patched firmware releases (12.4.3-03453+ and 12.5.0-02835+). CISA has added these CVEs to the Known Exploited Vulnerabilities (KEV) catalog and mandated immediate patching for U.S. federal agencies by July 17, 2026. Organizations without prompt remediation risk full device compromise, credential theft, and potential attack propagation internally.

Indicators of Compromise (IOCs) include unusual POST requests to “/api/login” or “/api/logout” returning HTTP 200, suspicious WebSocket proxy requests, log lines showing hotfix rollbacks with path traversal patterns, or presence of illegitimate API routes in “/var/lib/unit/conf.json”. No public proof-of-concept (PoC) code is available, but targeted attack activity has been confirmed across multiple regions and sectors. See recommendations below for prioritized response steps.

Recommendations for CVE-2026-15409, CVE-2026-15410

Immediate Actions:

  • Patch all affected SMA1000 appliances without delay. Upgrade to firmware 12.4.3-03453 or later (12.4 branch), or 12.5.0-02835 or later (12.5 branch). Patching is the only full mitigation for these vulnerabilities.
  • Restrict administrative and Work Place interface (port 8443) access to trusted internal networks via firewall or IP access control; block public internet access until patched.

Hardening and Long-Term Controls:

  • Enforce multi-factor authentication (MFA) for all admin interfaces.
  • Deploy upstream Web Application Firewall (WAF) protections for SSRF-like traffic patterns, if possible.
  • Enable HTTP Strict Transport Security (HSTS) where feasible.
  • Regularly monitor for new updates as threat intelligence evolves.
  • Integrate detection logic into SIEM/EDR tools for continuous monitoring.
  • Maintain robust internal segmentation to prevent lateral movement from the SMA appliance.

Compliance:

  • S. Federal Agencies: Must comply with CISA’s BOD 26-04 requirement and remediate by July 17, 2026.

Temporary Workarounds

  • Restrict access to SMA1000 management and Work Place interfaces to trusted IP ranges using firewalls or access controls as an interim measure before patching.
  • Temporarily disable the Work Place web interface, or limit exposure to internal use if possible.
  • Deploy log-monitoring scripts (e.g., Bash-based ‘ioc.sh’ from the SonicWall community) to detect suspicious API calls in appliance logs, but note that this does not prevent exploitation.
  • Applying configuration hardening, HSTS headers, and WAF signatures may reduce but not eliminate risk. These workarounds are not substitutes for patching and do not address root vulnerabilities.

References:

Share this post: