Exploited in the wild Secure Mobile Access (SMA) 1000 Series zero-day SonicWall privilege-escalation
SonicWall SMA zero-days were exploited weeks before disclosure
CVE Tools coverage
Researchers from Volexity have confirmed that two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 devices—CVE-2026-15409 and CVE-2026-15410—were actively exploited as zero-day flaws weeks before being publicly disclosed. These exploits enabled attackers to gain unauthorized access, install custom malware, and maintain persistent control over vulnerable systems. The attacks started as early as June 22, 2026, with threat actors leveraging these flaws to bypass security controls and exfiltrate sensitive data. SonicWall has issued patches, but experts warn that patching alone is insufficient; organizations must also check for signs of compromise and reset credentials.