Multiple vulnerabilities in Sonicwall Secure Mobile Access 1000 (July 15, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities have been discovered in Sonicwall Secure Mobile Access 1000. They allow an attacker to cause remote arbitrary code execution and server-side request forgery (SSRF). The vendor states that the vulnerabilities CVE-2026-15409 and...
CSIRTS triage
- What
- Vulnerabilities allow remote arbitrary code execution and server-side request forgery.
- Who is affected
- Deployments of Sonicwall Secure Mobile Access 1000.
- Urgency
- Remediation is urgent due to active exploitation.
- Action
- Update to the latest version provided by Sonicwall.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Secure Mobile Access 1000
Get an email when a new Secure Mobile Access 1000 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0875/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-15409Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 100% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15409 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] SonicWall SMA: Multiple vulnerabilitiescert-bund
- unknownexploitedNCSC-2026-0239 [1.00] [H/H] Zero-Day vulnerabilities fixed in SonicWall SMA1000ncsc-nl
- unknownSonicWall SMA1000 Series Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)cert-fr-alerte
- criticalexploitedSonicWall security advisory (AV26-699) – Update 1cccs
- criticalexploitedCVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Applianc…nvd
- criticalexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa-kev
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31