Published on August 3, 2026

Critical SonicWall SMA1000 Zero-Day Vulnerabilities Enable Root-Level Compromise


Severity

Critical

Detail

SonicWall has disclosed two actively exploited zero-day vulnerabilities affecting SonicWall SMA 1000 appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, the vulnerabilities can be chained to allow unauthenticated attackers to gain root-level access to affected internet-facing VPN gateways.

The attack begins by exploiting CVE-2026-15409, a critical pre-authentication vulnerability in the SMA WorkPlace WebSocket proxy (/wsproxy). By sending a specially crafted WebSocket request, attackers can establish a tunnel to internal services that are normally accessible only from localhost, effectively bypassing intended network restrictions.

Researchers found that CVE-2026-15409 allows attackers to communicate directly with internal services, including the Erlang distribution service used for internal remote procedure calls (RPC). By leveraging a hardcoded authentication cookie shared across affected appliances, attackers can execute arbitrary RPC commands, perform file operations, and obtain remote code execution on the device.

The second vulnerability, CVE-2026-15410, can be chained with CVE-2026-15409 to achieve full root-level control of the appliance. Successful exploitation may allow attackers to harvest plaintext LDAP credentials, access stored secrets, modify system files, and potentially intercept authentication traffic traversing the VPN gateway.

According to investigations conducted by Volexity, the vulnerabilities were exploited in the wild by a previously unidentified threat actor tracked as UTA0533 before SonicWall released security updates. Researchers also observed deployment of malware families including KnuckleBall, OrangeTail, and Suo5 on compromised systems.

SonicWall has released security updates addressing both vulnerabilities and recommends organizations immediately patch affected appliances and review systems for indicators of compromise.

CVE IDSummaryCVSS Score
CVE-2026-15409A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.10.0 (Critical)
CVE-2026-15410Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.7.2 (High)

Affected Products

The vulnerabilities affect the SonicWall SMA1000 Series (Models 6210, 7210, and 8200v) running the following versions:

  • 12.4.3-03245
  • 12.4.3-03387
  • 12.4.3-03434 (platform-hotfix)
  • 12.5.0-02283
  • 12.5.0-02624
  • 12.5.0-02800 (platform-hotfix)

These vulnerabilities do not affect SonicWall SSL-VPN running on SonicWall firewalls or the SonicWall SMA 100 Series product line.

Recommendation

Organizations using affected SonicWall SMA1000 Series appliances are strongly advised to perform the following actions:

  • Upgrade to the latest platform-hotfix version or a later supported release.
    • 12.4.3-03453 (platform-hotfix) or later
    • 12.5.0-02835 (platform-hotfix) or later
  • Perform a thorough forensic analysis of affected systems to identify any indicators of compromise (IoCs).
  • If indicators of compromise are identified:
    • Re-image physical appliances or re-deploy virtual appliances.
    • Change all user and administrator passwords.
    • Reset all Time-based One-Time Password (TOTP) tokens.

Source

https://gbhackers.com/sonicwall-sma-zero-days/

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

https://nvd.nist.gov/vuln/detail/CVE-2026-15409

https://nvd.nist.gov/vuln/detail/CVE-2026-15410