SonicWall warns SMA1000 users to apply urgent patches
SonicWall urges SMA1000 6210, 7210 and 8200v users to install hotfixes 12.4.3-03453 or 12.5.0-02835 for CVE-2026-15409 and CVE-2026-15410.
SonicWall is urging customers to immediately install hotfixes for two zero-day vulnerabilities affecting SMA1000 secure remote access appliances. The affected models are 6210, 7210 and 8200v. The vendor identified the patches as hotfix releases 12.4.3-03453 and 12.5.0-02835.
One flaw, tracked as CVE-2026-15409, is a server-side request forgery (SSRF) issue in the Appliance Work Place interface. The vulnerability can allow a remote, unauthenticated actor to force the appliance to send requests to unintended destinations. The second flaw, CVE-2026-15410, is a code injection vulnerability in the Appliance Management Console (AMC) that can allow an attacker with administrative access to execute arbitrary operating system commands.
SonicWall’s Product Security Incident Response Team (PSIRT) reported multiple cases that indicate active exploitation of these vulnerabilities and provided indicators of compromise to help customers detect intrusions. The advisory notes the two flaws may be chained to expand the impact of an attack. The advisory states, “SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.”
Cybersecurity firm Volexity assisted SonicWall’s investigation. The U.S. Cybersecurity and Infrastructure Security Agency added both CVEs to its Known Exploited Vulnerabilities catalog and set a remediation deadline of July 17 for federal agencies.
SonicWall published detection signatures and recommended steps to monitor for exploitation. Organizations using affected SMA1000 appliances should confirm device model and software version, install the specified hotfix for their release line, and apply the vendor’s detection guidance. For organizations unable to patch immediately, SonicWall recommended limiting administrative access to management interfaces, monitoring the provided indicators of compromise, and reviewing network controls to reduce exposure while updates are applied. Administrators needing technical information can consult SonicWall’s advisory and guidance from relevant national cybersecurity authorities.








