SonicWall SMA1000 Flaws Actively Exploited for SSRF and Remote Code Execution
SonicWall has issued an urgent security advisory (SNWLID-2026-0008) confirming active, in-the-wild exploitation of two critical vulnerabilities affecting its SMA1000 Series appliances. The flaws, trac

SonicWall has issued an urgent security advisory (SNWLID-2026-0008) confirming active, in-the-wild exploitation of two critical vulnerabilities affecting its SMA1000 Series appliances. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, allow attackers to chain an unauthenticated SSRF bug with a post-authentication code injection flaw to achieve full remote code execution on affected devices. CVE-2026-15409 is a maximum-severity […] The post SonicWall SMA1000 Flaws Actively Exploited for SSRF and Remote Code Execution appeared first on Cyber Security News.
SonicWall has issued an urgent security advisory (SNWLID-2026-0008) confirming active, in-the-wild exploitation of two critical vulnerabilities affecting its SMA1000 Series appliances. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, allow attackers to chain an unauthenticated SSRF bug with a post-authentication code injection flaw to achieve full remote code execution on affected devices. CVE-2026-15409 is a maximum-severity Server-Side Request Forgery (SSRF) vulnerability (CWE-918) residing in the SMA1000 Work Place interface. It requires no authentication or user interaction and can be triggered remotely over the network. SonicWall SMA1000 Flaws A successful attacker can coerce the appliance into issuing requests to arbitrary internal or external destinations, effectively bypassing network segmentation controls. CVE-2026-15410 is a code injection vulnerability (CWE-94) in the Management Console (AMC), rated 7.2 (High). While it requires administrator-level authentication, under specific conditions it enables an authenticated attacker to execute arbitrary OS commands on the underlying system. Sean Koessel and Steven Adair note that these two flaws form a dangerous exploit chain: SSRF grants an initial foothold or credential exposure, which attackers then leverage to reach the AMC and trigger the code-injection flaw for a full system compromise. Affected Products The flaws impact SMA1000 models 6210, 7210, and 8200v running firmware versions 12.4.3-03245 through 12.4.3-03434, and 12.5.0-02283 through 12.5.0-02800. Notably, SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected. Indicators of Compromise Organizations should audit logs for: HTTP 200 requests to /api/login or /api/logout in extraweb_access.log Suspicious host parameters in /wsproxy/wsproxy/wsproxy requests returning HTTP 101 status Hotfix rollback entries with path traversal naming patterns in ctrl-service.log Unauthorized routes for /api/login or /api/logout in /var/lib/unit/conf.json, which do not exist in legitimate configurations SonicWall urges customers to upgrade immediately to the fixed platform hotfix versions 12.4.3-03453 or 12.5.0-02835, or later, both available via mysonicwall.com. Organizations should also conduct a thorough forensic review for the IOCs listed above before assuming their systems are clean. If any compromise indicators are found, SonicWall recommends re-imaging or re-deploying affected appliances, rotating all user and administrator credentials, and resetting TOTP tokens across the environment. Give your SOC the intelligence it needs to act with confidence. Explore ANY.RUN Threat Intelligence Feeds to reduce noise and improve operational efficiency. The post SonicWall SMA1000 Flaws Actively Exploited for SSRF and Remote Code Execution appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


