Vulnerability Notification – SonicWall SMA1000 Zero-Days Actively Exploited
Created: Thursday, July 16, 2026 - 16:22
Categories:
(TLP:CLEAR) ACTION MAY BE REQUIRED for utilities using SonicWall Secure Mobile Access (SMA) 1000 Series remote access appliances (models 6210, 7210, and 8200v). Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Two zero-day vulnerabilities affecting SonicWall Secure Mobile Access (SMA) 1000 Series appliances are being actively exploited in the wild. Tracked as CVE-2026-15409 (CVSS 10.0), a server-side request forgery (SSRF) vulnerability in the SMA1000 Work Place interface allows a remote unauthenticated attacker to cause the appliance to make requests to an unintended location. The second, CVE-2026-15410 (CVSS 7.2), is a post-authentication code injection vulnerability in the Appliance Management Console (AMC) that, under specific conditions, could enable a remote authenticated attacker to execute arbitrary operating system commands as administrator. SonicWall’s PSIRT has investigated multiple cases indicating active exploitation of both vulnerabilities.
