Critical SSRF & Code‑Injection Vulnerabilities in SonicWall SMA 1000 Series (CVE‑2026‑15409, CVE‑2026‑15410)
What It Is — SonicWall disclosed two zero‑day flaws in its Secure Mobile Access (SMA) 1000 series appliances. CVE‑2026‑15409 is a critical server‑side request forgery (SSRF) that lets an unauthenticated attacker force the appliance to issue arbitrary network requests. CVE‑2026‑15410 is a high‑severity code‑injection bug in the management console that permits an authenticated admin to execute arbitrary OS commands.
Exploitability — Both vulnerabilities are confirmed to be actively exploited in the wild; attackers have been observed chaining the SSRF with the code‑injection to achieve remote code execution. CVSS v3.1 scores: 9.8 (Critical) for CVE‑2026‑15409 and 7.5 (High) for CVE‑2026‑15410.
Affected Products — SonicWall SMA 1000 series (models SMA6210, SMA7210, SMA8200v) running firmware versions 12.4.3‑03245 through 12.5.0‑02800.
Why It Matters for Compliance & Audit Readiness
- Control‑mapping requirement – SOC 2 Change Management (CC6.1) and System Operations (CC7.1) demand documented evidence that firmware baselines are tracked and updated. Mapping these patches to those controls provides a defensible audit trail.
- Continuous evidence – Capturing pre‑/post‑patch firmware versions, IOC logs, and remediation steps creates immutable artifacts that can be surfaced in a Trust Center for third‑party risk assessments.
- Beyond patching – SOC 2 also expects ongoing monitoring of security events. Reviewing logs for the published IOCs satisfies the “monitoring of security events” criterion and demonstrates due diligence to auditors and enterprise buyers.
Recommended Actions
- Apply the hot‑fixes (v12.4.3‑03453 and v12.5.0‑02835) immediately.
- Re‑image or redeploy affected hardware/virtual appliances and rotate all admin passwords and TOTP tokens.
- Collect immutable evidence – firmware version, patch checksum, log excerpts showing IOC detection, and remediation tickets.
- Map the activity to SOC 2 controls (CC6.1, CC7.1, CC7.2) and ingest the artifacts into your continuous‑compliance platform for audit readiness.
Source: Help Net Security – SonicWall SMA attacks via CVE‑2026‑15409 & CVE‑2026‑15410