Back to Blog
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA 1000 — Admin Command Execution Risk (July 2026)
vulnerabilities

CVE-2026-15409 & CVE-2026-15410: SonicWall SMA 1000 — Admin Command Execution Risk (July 2026)

breachwire TeamJul 16, 20262 min read

CVE-2026-15409 & CVE-2026-15410 — SonicWall SMA 1000

Two critical vulnerabilities (CVE-2026-15409, CVE-2026-15410) in SonicWall SMA 1000 series appliances are under active exploitation. CVE-2026-15409 is a server-side request forgery (SSRF) flaw, while CVE-2026-15410 enables post-authentication arbitrary code execution as admin. Both have been assigned critical severity and are included in the CISA Known Exploited Vulnerabilities catalog, mandating immediate remediation.

Attack Vector

Attackers exploit CVE-2026-15409 by sending crafted requests to internal API endpoints, such as /api/login or /api/logout, resulting in unauthorized SSRF. CVE-2026-15410 is leveraged post-authentication, allowing command injection via manipulated API calls, leading to arbitrary OS command execution with administrative privileges. Indicators of compromise include successful HTTP 200 requests to /api/login or /api/logout in extraweb_access.log, suspicious /wsproxy requests with unusual host parameters and HTTP 101 status, hotfix rollbacks with path traversal in ctrl-service.log, and unexpected routes in /var/lib/unit/conf.json.

Who Is at Risk

All organizations running SonicWall SMA 1000 series appliances are at risk, including Federal Civilian Executive Branch (FCEB) agencies. Both enterprise and government deployments are targeted, with confirmed exploitation in the wild.

Patch & Mitigate

  • Patch: Apply the latest SonicWall SMA 1000 security updates released July 2026. CISA mandates federal agencies to patch immediately.
  • Workaround: No effective workaround is available; patching is required.
  • Detect: Review extraweb_access.log for HTTP 200 requests to /api/login or /api/logout, /wsproxy requests with suspicious host parameters and HTTP 101 status, ctrl-service.log for hotfix rollbacks with path traversal, and /var/lib/unit/conf.json for unexpected API routes.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers leverage exposed APIs to gain initial foothold.
  • TA0007 — Discovery: SSRF enables attackers to probe internal network resources.
  • TA0009 — Execution: Post-authentication code injection leads to arbitrary command execution as admin.

Source: https://thehackernews.com/2026/07/two-sonicwall-sma-1000-zero-days.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: