Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
Two zero-day vulnerabilities in SonicWall SMA1000 Series devices—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410—are currently being actively exploited in attacks. The flaws allow unauthenticated attackers to create tunnels to internal services and escalate privileges to root. Rapid7’s MDR team detected real-world exploitation before official disclosure. Both issues are now listed in CISA’s KEV catalog. Affected versions include multiple firmware builds of models 6210, 7210, and 8200v. SonicWall has issued patches; users are urged to update immediately to prevent compromise.
Overview
On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409">CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CVE-2026-15410">CVE-2026-15410. The advisory urges customers to immediately apply the latest platform hotfix releases.…