Overview
- SonicWall confirmed on Tuesday that two zero‑day flaws in its SMA1000 remote‑access appliances are being actively exploited and released hotfixes in platform‑hotfix 12.4.3‑03453 and 12.5.0‑02835.
- The first flaw, CVE‑2026‑15409, is a critical server‑side request forgery (SSRF) that lets an unauthenticated attacker force the appliance to make requests to unintended locations.
- The second flaw, CVE‑2026‑15410, is a post‑authentication code injection in the appliance management console that can allow an authenticated admin to run arbitrary OS commands.
- CISA added both CVEs to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate affected systems by July 17, 2026, increasing immediate operational pressure on government and enterprise users.
- SonicWall published indicators of compromise and advises organizations to hunt logs, re‑image or redeploy compromised appliances, change all passwords, and reset TOTP tokens because patching alone may not remove active intrusions.