
[CIVN-2026-0371] Multiple Vulnerabilities in SonicWall
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in SonicWall
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
SonicWall Secure Mobile Access (SMA) 1000 Series appliances
Overview
Multiple vulnerabilities have been reported in SonicWall Secure Mobile Access (SMA) 1000 Series appliances, which could allow a remote attacker to perform Server-Side Request Forgery (SSRF) or execute arbitrary operating system commands on the affected systems.
Target Audience:
All end-user organizations and individuals using SonicWall Secure Mobile Access (SMA) 1000 Series appliances.
Risk Assessment:
Risk of arbitrary operating system command execution, Server-Side Request Forgery (SSRF), and compromise of affected systems.
Impact Assessment:
Potential for unauthorized requests to internal or unintended locations, arbitrary operating system command execution with administrative privileges, unauthorized access to resources reachable through the appliance and compromise of affected appliances.
Description
SonicWall Secure Mobile Access (SMA) 1000 Series appliances are secure remote access solutions used to provide secure access to enterprise networks and applications.
Multiple vulnerabilities have been identified in SonicWall Secure Mobile Access (SMA) 1000 Series appliances. These vulnerabilities include a Server-Side Request Forgery (SSRF) vulnerability and a post-authentication Code Injection vulnerability.
Successful exploitation of these vulnerabilities could allow an attacker to access internal or unintended network locations, execute arbitrary operating system commands and compromise the affected appliance.
Note: CVE-2026-15409 and CVE-2026-15410 are being actively exploited in the wild.
Solution
Apply appropriate security updates and mitigations as recommended by the vendor.
https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
Vendor Information
SonicWall
https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
References
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
CVE Name
CVE-2026-15409
CVE-2026-15410
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfiWMACgkQ3jCgcSdc
ys+SLg//VizT398UJ1veGmyex1MsBtwJXQRXX0SsI7Jmop6vYfAei4pFO6CmTTXg
vW7WGevF+ulFYLVh20kvSLAy8AO0iR/GI4QFrQMZMwvrRvbx9+H9KVTTMrkfa00F
lcrk4uVE8r6YXRw9cpl9Uc+YhXsHeLiDQBUKlJLLoYbT8s5s7zIKoWOmiZWsMJ5I
KbZlpamSjhJotMaLX4wNzHww89sQSEEEjWSLJSmqNUKhGpRLW0ddSJAkdnHxaVJP
e4RmXD11/f1r6zYMeRWG6gHkYZ+FVrAjViApqbl6jdS/IgbMvYbjR5rwSX3/pYJE
/Zv5gidtZlLyPyDQuXw/DT6h2TcdIS7uOeKxc+p+tRFZgs4KnRY89gYNhL8EU9Rv
hy1TmHqoAEMMKmZHVzg+R6flh1f+SDzWtNhFfYTJ1J1F1LzXYl/F/OLFKEL7Ob39
NgzcXYN3y2gWzF8rAb0YrqdKJB5mEgaYRky9nzqwa+yrwdFVzwVPNazkRhVsJJWu
FJnmjhRt0K6/FUnkoNzufB08jRr7W4bset35+RRq/dKL86y4Mt9QpcSiGUzsTCxd
ElBIh7euz1/DzGtgfQvB6KkxQig1JUVqHvwW30l/2tK8JNcHt1bOfznDtrty3YaS
zPCqaQ95mm9QUb04wcm9AXKe/BtxpmXTAVS9VRBLCiyihmdjylI=
=jYn6
—–END PGP SIGNATURE—–


