Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has issued a serious alert about two zero-day vulnerabilities affecting its SMA 1000 series Secure Mobile Access appliances, with one potentially allowing attackers to execute arbitrary commands. The more severe vulnerability, CVE-2026-15409, is a server-side request forgery (SSRF) flaw that even unauthenticated remote attackers can exploit. This situation is critical because it highlights the need for immediate patching and security reviews, especially for organizations relying on SonicWall's network security solutions. The implications could be widespread, given the high severity and active exploitation status.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.