CVE-2026-15409 – SonicWall SMA1000 Security Update

CVSS 10 CRITICAL Zero Day – Immediate Deployment

“An actively exploited critical vulnerability turns patching from routine maintenance into an urgent business priority.”

SonicWall has released security updates for two vulnerabilities affecting SMA1000 appliances. One vulnerability is being actively exploited and could allow an unauthenticated attacker to abuse a Server-Side Request Forgery (SSRF) weakness to force the appliance to send requests to unintended destinations. The second vulnerability is a post-authentication code injection issue that could allow an authenticated administrator to execute arbitrary operating system commands under specific conditions.

CVE-2026-15409 has a CVSS score of 10.0, which is Critical severity. CVE-2026-15410 has a CVSS score of 7.2, which is High severity. Verified active exploitation has been reported for both vulnerabilities, making timely deployment of this update essential to reduce the risk of system compromise and unauthorized activity.

Key Details

Affected Product
Sonicwall Sma6210 Firmware
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-918
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.