Are You Confident in the Security of Your SonicWall SMA1000 Appliance? Cybercriminals Are Already Actively Exploiting Critical Zero-Day Vulnerabilities!

Imported from official source

Announcement

The most severe of the disclosed vulnerabilities is CVE-2026-15409, which has received the maximum CVSS score of 10.0.

This vulnerability is a Server-Side Request Forgery (SSRF) flaw affecting the SMA1000 Workplace interface. Its most alarming characteristic is that no authentication is required for exploitation. In other words, a remote attacker can send specially crafted requests to a vulnerable appliance without needing a valid username or password.

By exploiting this SSRF vulnerability, an attacker may:

  • Discover internal services that are not directly accessible from the Internet;
  • Establish a foothold for launching attacks against other systems;
  • Build additional exploitation chains leading to further compromise.
  • SSRF vulnerabilities are particularly dangerous because they can provide attackers with covert access to an organization’s internal infrastructure.

    The second vulnerability, tracked as CVE-2026-15410, has been assigned a CVSS score of 7.2.

    This issue affects the SMA1000 Appliance Management Console and is classified as a Code Injection vulnerability.

    Exploiting this flaw requires administrative privileges. If an attacker succeeds in compromising an administrator account or hijacking an active administrator session, they may execute arbitrary operating system commands and gain complete control over the appliance.

    The vulnerabilities impact the following SonicWall SMA1000 models:

    The issues have been identified in certain 12.4.3 and 12.5.0 platform hotfix releases.

    SonicWall has also confirmed that these vulnerabilities do not affect:

    SonicWall’s Product Security Incident Response Team (PSIRT) has investigated multiple real-world cyberattacks in which these vulnerabilities were successfully exploited.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/are-you-confident-in-the-security-of-your-sonicwall-sma1000-appliance-cybercriminals-are-already-actively-exploiting-critical-zero-day-vulnerabilities/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39190

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.