CVE Tools
Back to feed
Exploited in the wild Secure Mobile Access (SMA) 1000 Series zero-day SonicWall privilege-escalation

SonicWall SMA zero-days were exploited weeks before disclosure

Help Net Security·By Zeljka Zorz··3 min read
CVE Tools coverage

Researchers from Volexity have confirmed that two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 devices—CVE-2026-15409 and CVE-2026-15410—were actively exploited as zero-day flaws weeks before being publicly disclosed. These exploits enabled attackers to gain unauthorized access, install custom malware, and maintain persistent control over vulnerable systems. The attacks started as early as June 22, 2026, with threat actors leveraging these flaws to bypass security controls and exfiltrate sensitive data. SonicWall has issued patches, but experts warn that patching alone is insufficient; organizations must also check for signs of compromise and reset credentials.