HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Zero‑Day SSRF (CVE‑2026‑15409) and Code‑Injection (CVE‑2026‑15410) in SonicWall SMA1000 Actively Exploited – Patch Required

SonicWall reports active exploitation of two critical flaws in its SMA1000 appliances—CVE‑2026‑15409 (SSRF, CVSS 10.0) and CVE‑2026‑15410 (post‑auth code injection, CVSS 7.2). The vendor has issued hotfixes; organizations must patch and verify compromise to stay audit‑ready under SOC 2.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Critical SSRF (CVE‑2026‑15409) & High‑Severity Code‑Injection (CVE‑2026‑15410) in SonicWall SMA1000 Appliances Actively Exploited – Patch Now

What It Is – SonicWall disclosed two zero‑day flaws in its SMA1000 series: a critical SSRF (CVE‑2026‑15409, CVSS 10.0) that lets an unauthenticated attacker force the appliance to reach arbitrary internal services, and a high‑severity post‑auth code‑injection (CVE‑2026‑15410, CVSS 7.2) that permits an authenticated admin to run OS commands.

Exploitability – Both CVEs are confirmed to be under active exploitation. No public PoC is required; attackers are already leveraging the SSRF to pivot inside target networks, and the code‑injection is being used where admin credentials exist.

Affected Products – SonicWall SMA1000 models 6210, 7210, and 8200v on hot‑fix releases 12.4.3‑03245 through 12.5.0‑02800. Patches are available in 12.4.3‑03453 and 12.5.0‑02835 (or later).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Control Mapping: The flaws directly impact the System Operations and Change Management criteria; mapping them to your control matrix demonstrates due‑diligence.
  • Continuous Evidence: Verifying patch deployment and IOC scans provides immutable audit evidence that the organization maintains a defended‑state, a key requirement for the Security principle.
  • Defensible Audit Trail: Documenting remediation steps (hotfix version, re‑imaging, password rotation) creates a traceable trail that auditors can review, reducing “control‑gap” findings.

Recommended Actions

  • Deploy the SonicWall hotfixes (12.4.3‑03453 / 12.5.0‑02835) immediately.
  • Run the supplied IOC checks in extraweb_access.log and ctrl-service.log to detect compromise.
  • If compromise is confirmed, re‑image or redeploy the appliance, rotate all local and admin passwords, and reset TOTP tokens.
  • Record remediation details in your SOC 2 control evidence repository (e.g., Verisq Trust Center) to satisfy continuous‑compliance requirements.

Source: BleepingComputer – SonicWall warns of SMA1000 flaws exploited in zero‑day attacks, patch now

📰 Original Source
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →