CVE-2026-15409 – SonicWall SMA1000 Security Update
“An actively exploited critical vulnerability turns patching from routine maintenance into an urgent business priority.”
SonicWall has released security updates for two vulnerabilities affecting SMA1000 appliances. One vulnerability is being actively exploited and could allow an unauthenticated attacker to abuse a Server-Side Request Forgery (SSRF) weakness to force the appliance to send requests to unintended destinations. The second vulnerability is a post-authentication code injection issue that could allow an authenticated administrator to execute arbitrary operating system commands under specific conditions.
CVE-2026-15409 has a CVSS score of 10.0, which is Critical severity. CVE-2026-15410 has a CVSS score of 7.2, which is High severity. Verified active exploitation has been reported for both vulnerabilities, making timely deployment of this update essential to reduce the risk of system compromise and unauthorized activity.
Key Details
- Affected Product
- Sonicwall Sma6210 Firmware
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-918