Are You Confident in the Security of Your SonicWall SMA1000 Appliance? Cybercriminals Are Already Actively Exploiting Critical Zero-Day Vulnerabilities!
The most severe of the disclosed vulnerabilities is CVE-2026-15409, which has received the maximum CVSS score of 10.0.
This vulnerability is a Server-Side Request Forgery (SSRF) flaw affecting the SMA1000 Workplace interface. Its most alarming characteristic is that no authentication is required for exploitation. In other words, a remote attacker can send specially crafted requests to a vulnerable appliance without needing a valid username or password.
By exploiting this SSRF vulnerability, an attacker may:
SSRF vulnerabilities are particularly dangerous because they can provide attackers with covert access to an organization’s internal infrastructure.
The second vulnerability, tracked as CVE-2026-15410, has been assigned a CVSS score of 7.2.
This issue affects the SMA1000 Appliance Management Console and is classified as a Code Injection vulnerability.
Exploiting this flaw requires administrative privileges. If an attacker succeeds in compromising an administrator account or hijacking an active administrator session, they may execute arbitrary operating system commands and gain complete control over the appliance.
The vulnerabilities impact the following SonicWall SMA1000 models:
The issues have been identified in certain 12.4.3 and 12.5.0 platform hotfix releases.
SonicWall has also confirmed that these vulnerabilities do not affect:
SonicWall’s Product Security Incident Response Team (PSIRT) has investigated multiple real-world cyberattacks in which these vulnerabilities were successfully exploited.
This is an extract. The publication continues at the source.
Read the original at the source: https://uzcert.uz/en/are-you-confident-in-the-security-of-your-sonicwall-sma1000-appliance-cybercriminals-are-already-actively-exploiting-critical-zero-day-vulnerabilities/
Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- UZCERT — imported from official source
- Official source
- https://uzcert.uz/en/feed/ RSS
- Imported
- October 03, 2026 20:40
- Versions
- 1 recorded
- Identity
https://uzcert.uz/?p=39190