The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding two critical vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series appliances. These vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, are currently being exploited in ransomware attacks, prompting their addition to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
SonicWall disclosed these vulnerabilities on July 14, 2026, under advisory SNWLID-2026-0008. The affected products include SMA 6210, SMA 7210, and SMA 8200v appliances running specific platform-hotfix releases of versions 12.4.3 and 12.5.0. Notably, SonicWall’s firewall SSL-VPN services and the SMA 100 Series product line remain unaffected.
Details of the Vulnerabilities
CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability in the SMA1000 Workplace interface, carrying a CVSS severity score of 10.0. This flaw allows remote attackers to make the appliance send requests to unintended internal or external locations without requiring authentication or user interaction. Exploiting this vulnerability can enable attackers to access services that are otherwise inaccessible from the public internet.
CVE-2026-15410 is a code injection vulnerability in the SMA1000 Appliance Management Console, with a CVSS score of 7.2. Under certain conditions, an authenticated administrator can execute arbitrary operating system commands. Attackers can chain these two vulnerabilities: the SSRF flaw provides access to protected internal functionalities, while the code injection flaw allows escalation to root-level control of the appliance.
Implications and Recommendations
The exploitation of these vulnerabilities is particularly concerning because SMA1000 devices often serve as gateways for remote user access to corporate networks. A successful compromise could lead to credential theft, unauthorized access to session information, establishment of persistence within the network, lateral movement to internal systems, and the deployment of ransomware.
Reports indicate that the INC Ransomware operation has been actively exploiting this vulnerability chain, with earlier activities linked to a threat actor cluster identified as UTA0533.
SonicWall has released patched versions 12.4.3-03453 and 12.5.0-02835 to address these vulnerabilities. Given the absence of viable workarounds, immediate patching is imperative. CISA mandated that U.S. federal agencies apply these patches by July 17, 2026, and urged all organizations to check for signs of compromise before considering the issue resolved.
Organizations should review logs for unexpected requests involving specific API endpoints, monitor for suspicious hotfix rollback activities, and inspect configuration files for unauthorized routes. If indicators of compromise are detected, SonicWall recommends re-imaging physical appliances or redeploying virtual ones, changing all user and administrator passwords, and resetting two-factor authentication tokens.
Given the critical nature of these vulnerabilities and their active exploitation, organizations using affected SMA1000 appliances should prioritize patching and conduct thorough investigations to ensure their systems have not been compromised.