Two SonicWall SMA 1000 Zero-Days Are Being Actively Exploited

SonicWall has warned customers about two zero-day flaws in Secure Mobile Access, or SMA 1000 Series appliances. This issue is serious because the flaws are already being exploited in active attacks. So, this is not just a theoretical risk. The two flaws are CVE-2026-15409 and CVE-2026-15410. One of them has a CVSS score of 10.0, which makes it critical. Because SMA devices are used for remote access, they are attractive targets for attackers.

What Is SonicWall SMA 1000?

SonicWall SMA 1000 is a secure remote access appliance. It helps users connect to company resources from outside the office.

Companies often use this type of tool for remote workers, vendors, and teams that need access to internal applications.

Since the appliance sits at the network edge, it is a critical asset. If attackers compromise it, they may get closer to the internal network.

This is why remote access flaws need fast action.

Why These Flaws Matter

These flaws matter because they affect a perimeter device.

Perimeter devices, such as firewalls, VPNs, and remote access gateways, often become initial access points. If attackers get in through this layer, they may try to move deeper into the network.

Also, SMA appliances often connect to internal identity systems. These may include LDAP or Active Directory.

As a result, a compromised SMA appliance can create wider risk. This may include credential theft, unauthorized access, and lateral movement.

CVE-2026-15409: Critical SSRF Flaw

CVE-2026-15409 is a server-side request forgery, or SSRF, flaw. It has a CVSS score of 10.0.

SSRF happens when an attacker can make a server send requests to unintended locations.

In this case, a remote unauthenticated attacker may abuse the flaw. The appliance may then reach internal services that should not be reachable from the outside.

The risk is very high because no login is required. So, internet-facing SMA appliances need urgent review.

CVE-2026-15410: Code Injection After Login

CVE-2026-15410 is a code injection flaw. It affects the Appliance Management Console, or AMC.

Unlike the first flaw, this one requires authentication. Still, the impact can be serious.

If exploited, an attacker may run operating system commands as administrator under certain conditions.

This flaw becomes more dangerous when chained with another issue. In real attacks, attackers may use one flaw to reach the next one.

Active Exploitation Has Been Observed

Rapid7 reported active exploitation of internet-facing SMA 1000 appliances.

According to the report, attackers used the appliance as an initial access point. After gaining a foothold, they tried to collect high-value data from the device.

This data may include credentials, active session databases, and TOTP MFA seed configurations.

That is very dangerous. If MFA seed data is stolen, attackers may try to keep access even after normal remediation steps.

Lateral Movement Risk

After compromising the SMA appliance, attackers may try to move into the internal network.

Rapid7 also observed unusual authentication activity against domain controllers. The activity came from the internal IP address of the appliance.

This suggests that a compromised appliance can act as a backdoor. In other words, attackers may not need a normal VPN session.

For companies, this is a major warning sign. A compromised perimeter appliance should be treated as a high-risk asset.

Versions That Need Updates

SonicWall has released fixes through platform hotfix versions.

The fixed versions are 12.4.3-03453 platform-hotfix or later. For the other release line, use 12.5.0-02835 platform-hotfix or later.

If an organization still uses an older affected version, patching should be done quickly. Internet-facing devices should be the top priority.

Also, organizations should check all SMA 1000 appliances in use. Do not only check the main production device.

Are All SonicWall Products Affected?

Not all SonicWall products are affected by these flaws.

Rapid7 says the issue affects SMA 1000 Series appliances. The listed models include 6210, 7210, and 8200v.

The issue does not affect SSL VPN functionality on SonicWall firewalls. It also does not affect the SMA 100 Series product line.

Still, IT teams should confirm the exact model and version in their environment. Product names can be easy to confuse.

Indicators IT Teams Should Check

IT teams should perform a forensic review on affected appliances.

Several logs should be reviewed. These include extraweb_access.log, ctrl-service.log, and certain appliance configuration files.

Look for suspicious requests to login, logout, or wsproxy endpoints. Also, check for unusual hotfix rollback activity.

If indicators of compromise appear, do not rely on patching alone. Treat the appliance as potentially compromised.

Recommended Mitigation Steps

The first step is to update to the latest platform hotfix version. This should be the top priority.

After that, perform a forensic review. Look for signs of exploitation in logs and appliance configuration.

If compromise is found, re-image physical appliances. For virtual appliances, redeploy them.

Also, change user and administrator passwords. Reset TOTP tokens if there are signs of compromise.

This matters because attackers may have already collected credentials or session data before the patch was applied.

Extra Tips for Organizations

Create an inventory of all remote access appliances. Make sure IT knows which devices are exposed to the internet.

Next, restrict access to management interfaces. Use IP allowlists, a dedicated admin VPN, or network segmentation.

Also, monitor authentication activity to Active Directory. Watch for logins from unusual sources or suspicious workstation names.

Finally, send perimeter appliance logs to a SIEM. This helps security teams detect abnormal behavior faster.

Key Takeaway

These two SonicWall SMA 1000 zero-days need urgent action. One flaw has a CVSS score of 10.0 and can be exploited without authentication.

The risk is not limited to the appliance itself. If attackers gain access, the internal network may also be at risk.

For this reason, organizations should patch quickly, check for compromise, rotate credentials, and strengthen perimeter access controls.

In the end, remote access appliances must be treated as critical assets. If they face the internet, patching and monitoring must be strict.