SonicWall SMA1000: active exploitation of CVE-2026-15409 and CVE-2026-15410

SonicWall confirms active exploitation of CVE-2026-15409 and CVE-2026-15410 in SMA1000 appliances. Fixed versions, indicators, and response steps.

Share

SonicWall has confirmed active exploitation of two vulnerabilities in SMA1000 remote-access appliances: CVE-2026-15409 and CVE-2026-15410. The affected products are SMA1000 models 6210, 7210, and 8200v. SonicWall states that its firewall SSL-VPN products and the SMA 100 Series are not affected.

This is an appliance incident, not a generic SonicWall firewall incident. Identify every SMA1000 device, its platform-hotfix version, and whether it was internet-facing before the fixed hotfix was installed.

The two flaws

CVE-2026-15409 is an unauthenticated server-side request forgery in the SMA1000 Work Place interface. SonicWall scores it CVSS 10.0 and says an unauthenticated remote attacker can cause the appliance to make requests to unintended locations.

CVE-2026-15410 is a post-authentication code-injection issue in the SMA1000 Appliance Management Console. SonicWall says a remote attacker authenticated as an administrator can, in specific conditions, execute arbitrary operating-system commands. The vendor score is CVSS 7.2. It is not an unauthenticated flaw on its own.

Rapid7 reports that the vulnerabilities were used together against internet-facing appliances before the advisory was published. Treat the pair as an incident-response priority even if the appliance was patched after the disclosure.

Affected and fixed versions

SonicWall lists these affected platform-hotfix versions: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.

The vendor lists 12.4.3-03453 platform-hotfix or later and 12.5.0-02835 platform-hotfix or later as fixed. There is no workaround. Download the current platform hotfix through MySonicWall, apply it, and record the version installed. A version check is necessary, but it is not a compromise assessment.

Check for compromise

SonicWall recommends checking extraweb_access.log for requests to /__api__/login or /__api__/logout returning HTTP 200, and requests to /wsproxy with suspicious host parameters returning HTTP 101. Review ctrl-service.log for hotfix rollbacks with path-traversal names. Also examine /var/lib/unit/conf.json for routes for /__api__/login or /__api__/logout. SonicWall states that these routes do not exist in a legitimate configuration.

These are leads, not proof of absence. Preserve logs and appliance configuration before a rebuild if possible. If an indicator is present, SonicWall recommends re-imaging hardware appliances or redeploying virtual appliances, changing user and administrator passwords, and resetting TOTP tokens.

Immediate response plan

Identify SMA1000 devices and isolate externally exposed administration paths where operationally possible. Apply the fixed platform hotfix. Collect and review the vendor-listed logs and configuration artifacts. If an indicator is present, rebuild or redeploy the appliance rather than relying only on cleanup. Rotate credentials and reset TOTP tokens after a suspected compromise. Review identity-provider, VPN, and administrative activity around the period the appliance was exposed.

CVE-2026-15410 requires administrator authentication. Retain that distinction in any summary. Do not apply this advisory to SonicWall firewall SSL-VPN or the SMA 100 product line.

Sources

SonicWall PSIRT SNWLID-2026-0008

SonicWall product notice

Rapid7 MDR analysis

NVD: CVE-2026-15410

Topics: