Critical SSRF (CVE‑2026‑15409) & High‑Severity Code‑Injection (CVE‑2026‑15410) in SonicWall SMA1000 Appliances Actively Exploited – Patch Now
What It Is – SonicWall disclosed two zero‑day flaws in its SMA1000 series: a critical SSRF (CVE‑2026‑15409, CVSS 10.0) that lets an unauthenticated attacker force the appliance to reach arbitrary internal services, and a high‑severity post‑auth code‑injection (CVE‑2026‑15410, CVSS 7.2) that permits an authenticated admin to run OS commands.
Exploitability – Both CVEs are confirmed to be under active exploitation. No public PoC is required; attackers are already leveraging the SSRF to pivot inside target networks, and the code‑injection is being used where admin credentials exist.
Affected Products – SonicWall SMA1000 models 6210, 7210, and 8200v on hot‑fix releases 12.4.3‑03245 through 12.5.0‑02800. Patches are available in 12.4.3‑03453 and 12.5.0‑02835 (or later).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Control Mapping: The flaws directly impact the System Operations and Change Management criteria; mapping them to your control matrix demonstrates due‑diligence.
- Continuous Evidence: Verifying patch deployment and IOC scans provides immutable audit evidence that the organization maintains a defended‑state, a key requirement for the Security principle.
- Defensible Audit Trail: Documenting remediation steps (hotfix version, re‑imaging, password rotation) creates a traceable trail that auditors can review, reducing “control‑gap” findings.
Recommended Actions
- Deploy the SonicWall hotfixes (12.4.3‑03453 / 12.5.0‑02835) immediately.
- Run the supplied IOC checks in
extraweb_access.logandctrl-service.logto detect compromise. - If compromise is confirmed, re‑image or redeploy the appliance, rotate all local and admin passwords, and reset TOTP tokens.
- Record remediation details in your SOC 2 control evidence repository (e.g., Verisq Trust Center) to satisfy continuous‑compliance requirements.
Source: BleepingComputer – SonicWall warns of SMA1000 flaws exploited in zero‑day attacks, patch now