Posting Date: 2026/07/22 \
【Vulnerability Alert】Multiple High-Risk Security Vulnerabilities Exist in SonicWall SMA 1000 Series (CVE-2026-15409 and CVE-2026-15410); Please Confirm and Apply Patches As Soon As Possible
- Subject: 【Vulnerability Alert】Multiple High-Risk Security Vulnerabilities Exist in SonicWall SMA 1000 Series (CVE-2026-15409 and CVE-2026-15410); Please Confirm and Apply Patches As Soon As Possible
\
- Description:
- Forwarded from National Information Sharing and Analysis Center Security Advisory NISAC-200-202607-00000005.
- Researchers have discovered multiple high-risk security vulnerabilities in the SonicWall SMA 1000 series (CVE-2026-15409 and CVE-2026-15410), categorized as Server-Side Request Forgery (SSRF) and Code Injection, respectively. Both vulnerabilities have been exploited by attackers; please confirm and apply patches as soon as possible. CVE-2026-15409: An unauthenticated remote attacker can send specially crafted requests to the Work Place interface of SMA 1000 devices, causing the system to send requests to unintended locations. CVE-2026-15410: A remote attacker with administrative privileges can execute arbitrary operating system commands in the Appliance Management Console (AMC).
- Affected Platforms:
- SonicWall SMA 1000 series (6210, 7210, and 8200v)
- platform-hotfix versions 12.4.3-03245, 12.4.3-03387, and 12.4.3-03434
- platform-hotfix versions 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800
- Recommended Actions:
- The vendor has released security updates for these vulnerabilities. Please upgrade to the following versions and refer to the official advisory for instructions: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- References:
Computer and Communication Center \ Network System Division