[CIVN-2026-0371] Multiple Vulnerabilities in SonicWall

By Published On: July 21, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in SonicWall


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


SonicWall Secure Mobile Access (SMA) 1000 Series appliances

Overview


Multiple vulnerabilities have been reported in SonicWall Secure Mobile Access (SMA) 1000 Series appliances, which could allow a remote attacker to perform Server-Side Request Forgery (SSRF) or execute arbitrary operating system commands on the affected systems.


Target Audience:

All end-user organizations and individuals using SonicWall Secure Mobile Access (SMA) 1000 Series appliances.


Risk Assessment:

Risk of arbitrary operating system command execution, Server-Side Request Forgery (SSRF), and compromise of affected systems.


Impact Assessment:

Potential for unauthorized requests to internal or unintended locations, arbitrary operating system command execution with administrative privileges, unauthorized access to resources reachable through the appliance and compromise of affected appliances.


Description


SonicWall Secure Mobile Access (SMA) 1000 Series appliances are secure remote access solutions used to provide secure access to enterprise networks and applications.


Multiple vulnerabilities have been identified in SonicWall Secure Mobile Access (SMA) 1000 Series appliances. These vulnerabilities include a Server-Side Request Forgery (SSRF) vulnerability and a post-authentication Code Injection vulnerability.


Successful exploitation of these vulnerabilities could allow an attacker to access internal or unintended network locations, execute arbitrary operating system commands and compromise the affected appliance.


Note: CVE-2026-15409 and CVE-2026-15410 are being actively exploited in the wild.


Solution


Apply appropriate security updates and mitigations as recommended by the vendor.

https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008



Vendor Information


SonicWall

https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008


References


 

https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/

https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008


CVE Name

CVE-2026-15409

CVE-2026-15410




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfiWMACgkQ3jCgcSdc

ys+SLg//VizT398UJ1veGmyex1MsBtwJXQRXX0SsI7Jmop6vYfAei4pFO6CmTTXg

vW7WGevF+ulFYLVh20kvSLAy8AO0iR/GI4QFrQMZMwvrRvbx9+H9KVTTMrkfa00F

lcrk4uVE8r6YXRw9cpl9Uc+YhXsHeLiDQBUKlJLLoYbT8s5s7zIKoWOmiZWsMJ5I

KbZlpamSjhJotMaLX4wNzHww89sQSEEEjWSLJSmqNUKhGpRLW0ddSJAkdnHxaVJP

e4RmXD11/f1r6zYMeRWG6gHkYZ+FVrAjViApqbl6jdS/IgbMvYbjR5rwSX3/pYJE

/Zv5gidtZlLyPyDQuXw/DT6h2TcdIS7uOeKxc+p+tRFZgs4KnRY89gYNhL8EU9Rv

hy1TmHqoAEMMKmZHVzg+R6flh1f+SDzWtNhFfYTJ1J1F1LzXYl/F/OLFKEL7Ob39

NgzcXYN3y2gWzF8rAb0YrqdKJB5mEgaYRky9nzqwa+yrwdFVzwVPNazkRhVsJJWu

FJnmjhRt0K6/FUnkoNzufB08jRr7W4bset35+RRq/dKL86y4Mt9QpcSiGUzsTCxd

ElBIh7euz1/DzGtgfQvB6KkxQig1JUVqHvwW30l/2tK8JNcHt1bOfznDtrty3YaS

zPCqaQ95mm9QUb04wcm9AXKe/BtxpmXTAVS9VRBLCiyihmdjylI=

=jYn6

—–END PGP SIGNATURE—–

Share this article