Security & Threat Intelligence · 25.07.2026, 15:30 UTC
CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| CVE | ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Tenable Research ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch. Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2019-7481, CVE-2019-7483, CVE-2021-20016, CVE-2021-20038, CVE-2024-40766. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators of compromise are available and urgent patching is recommended.BackgroundSonicWall's Secure Mobile Access (SMA) 1000 Series appliances are enterprise-grade SSL VPN gateways which serve as the front door to organizational networks. The SMA series models sit at the edge of the network, internet-facing by design. Because SMA 1000 appliances aggregate remote access credentials and sit directly on the internet, they represent high-value targets for attackers. A compromise at the appliance level can yield administrator credentials, VPN session tokens, and detailed knowledge of the internal network architecture sitting behind the gateway.On July 14, SonicWall disclosed two vulnerabilities that are being exploited together in the wild:CVEDescriptionCVSSv3CVE-2026-15409SonicWall SMA 1000 server-side request forgery (SSRF) vulnerability10CVE-2026-15410SonicWall SMA 1000 remote code execution vulnerability (RCE)7.2While the advisory does not specify if they were exploited in tandem, together they form a fully remote, unauthenticated path to arbitrary OS command execution on affected …