DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-15409PUBLISHED: 2026-07-14
CRITICALCVE-2026-15409★ CISA KEV LISTED

SonicWall SMA1000 Unauthenticated SSRF Zero-Day

VENDOR: SonicWall//PRODUCT: Secure Mobile Access (SMA) 1000 Series
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

A maximum-severity (CVSS 10.0) unauthenticated server-side request forgery (SSRF) in the SMA1000 Appliance Work Place interface allows a remote attacker to open a WebSocket-based tunnel to arbitrary localhost-only services, effectively bypassing network segmentation. Rapid7 MDR observed active zero-day exploitation of internet-facing SMA1000 appliances prior to SonicWall's official disclosure, and SonicWall PSIRT confirmed multiple in-the-wild exploitation cases. Both CVE-2026-15409 and CVE-2026-15410 are frequently chained together to achieve OS-level command execution on compromised appliances; no public PoC has been published but working private exploit tooling is confirmed in use.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSMA1000 models 6210, 7210, 8200v running firmware 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, 12.5.0-02800
  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
  • https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/
  • https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
  • https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog
  • https://www.sophos.com/en-us/blog/sonicwall-sma1000-vulnerabilities-in-active-exploitation
SHARE BRIEF:✕ Post on Xin Share on LinkedIn