Summary

SonicWall issued an urgent security advisory this week warning customers that two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances are being actively exploited in the wild. Both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities catalog, and federal agencies have been directed to patch immediately.

CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability scoring a perfect CVSS 10.0, allowing a remote unauthenticated attacker to make arbitrary outbound requests from the appliance. CVE-2026-15410 is a post-authentication code injection flaw (CVSS 7.2) that enables arbitrary OS command execution as an administrator. Together, the two flaws form a potent chain: SSRF for initial foothold and reconnaissance, code injection for full system takeover once credentials are obtained or bypassed.

SMA 1000 appliances are widely deployed as remote access gateways in enterprise and government environments, making them a high-value target. SonicWall has released patches and is urging all customers to update immediately, restrict management interface access, and review logs for indicators of compromise.

Sources

Commentary

Remote access appliances remain one of the most reliable initial-access vectors in 2026, and SonicWall has unfortunately been a recurring target. A CVSS 10.0 unauthenticated SSRF on an internet-facing gateway is as bad as it gets — these devices are designed to sit on the perimeter, making pre-authentication exploits extremely dangerous. If you’re running SMA 1000 in your environment, this is a drop-everything patch.

The SSRF-to-code-injection chain is a classic two-step that’s especially nasty in VPN/remote-access appliances because they typically have privileged network positions, trust relationships with internal services, and are accessible from the internet by design. There’s no good reason to delay here — check your patch status now.

By Allan