Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Zero‑Day SSRF (CVE‑2026‑15409) and Code‑Injection (CVE‑2026‑15410) in SonicWall SMA1000 Actively Exploited – Patch Required

SonicWall reports active exploitation of two critical flaws in its SMA1000 appliances—CVE‑2026‑15409 (SSRF, CVSS 10.0) and CVE‑2026‑15410 (post‑auth code injection, CVSS 7.2). The vendor has issued hotfixes; organizations must patch and verify compromise to stay audit‑ready under SOC 2.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Critical SSRF (CVE‑2026‑15409) & High‑Severity Code‑Injection (CVE‑2026‑15410) in SonicWall SMA1000 Appliances Actively Exploited – Patch Now

What It Is – SonicWall disclosed two zero‑day flaws in its SMA1000 series: a critical SSRF (CVE‑2026‑15409, CVSS 10.0) that lets an unauthenticated attacker force the appliance to reach arbitrary internal services, and a high‑severity post‑auth code‑injection (CVE‑2026‑15410, CVSS 7.2) that permits an authenticated admin to run OS commands.

Exploitability – Both CVEs are confirmed to be under active exploitation. No public PoC is required; attackers are already leveraging the SSRF to pivot inside target networks, and the code‑injection is being used where admin credentials exist.

Affected Products – SonicWall SMA1000 models 6210, 7210, and 8200v on hot‑fix releases 12.4.3‑03245 through 12.5.0‑02800. Patches are available in 12.4.3‑03453 and 12.5.0‑02835 (or later).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Control Mapping: The flaws directly impact the System Operations and Change Management criteria; mapping them to your control matrix demonstrates due‑diligence.
  • Continuous Evidence: Verifying patch deployment and IOC scans provides immutable audit evidence that the organization maintains a defended‑state, a key requirement for the Security principle.
  • Defensible Audit Trail: Documenting remediation steps (hotfix version, re‑imaging, password rotation) creates a traceable trail that auditors can review, reducing “control‑gap” findings.

Recommended Actions

  • Deploy the SonicWall hotfixes (12.4.3‑03453 / 12.5.0‑02835) immediately.
  • Run the supplied IOC checks in extraweb_access.log and ctrl-service.log to detect compromise.
  • If compromise is confirmed, re‑image or redeploy the appliance, rotate all local and admin passwords, and reset TOTP tokens.
  • Record remediation details in your SOC 2 control evidence repository (e.g., Verisq Trust Center) to satisfy continuous‑compliance requirements.

Source: BleepingComputer – SonicWall warns of SMA1000 flaws exploited in zero‑day attacks, patch now

📰 Original Source
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →