SonicWall SMA 1000: Two Zero-Days Are Already Being Exploited, One May Enable Command Execution

Colleagues, a cybersecurity alert: SonicWall has confirmed active exploitation of two zero-days in SMA 1000.
In brief:
• CVE-2026-15409 — a critical SSRF flaw rated 10.0.
• CVE-2026-15410 — a post-auth code injection issue that, under certain conditions, may enable OS command execution as administrator.
• Patches are already available and should be applied without delay.
SonicWall also recommends checking IoCs and, if compromise is suspected, reinstalling the appliance, changing passwords, and resetting OTP tokens.
Why this matters: active exploitation means the response window is already very short.
Have you checked your SMA 1000 for IoCs?
#cybersecurity #zeroday #SonicWall #IncidentResponse

