NCSC-2026-0239 [1.00] [H/H] Zero-Day vulnerabilities fixed in SonicWall SMA1000
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
SonicWall has fixed two vulnerabilities in SonicWall SMA1000 appliances. The vulnerability identified as CVE-2026-15409 is a Server-Side Request Forgery (SSRF) in the Work Place interface, allowing an unauthenticated attacker to make the device send requests to unwanted locations. The vulnerability identified as CVE-2026-15410 is a post-authentication code injection in the Appliance Management Console (AMC), allowing an authenticated attacker with admin rights to execute arbitrary OS commands on the device. Both vulnerabilities have been exploited as zero-days. The NCSC advises organizations to follow SonicWall's advisory, check for the presence of the attached IoCs, and carry out the recommended actions.
CSIRTS triage
- What
- Two vulnerabilities allow an unauthenticated attacker to exploit SSRF and an authenticated attacker to execute arbitrary OS commands.
- Who is affected
- SonicWall SMA1000 appliance users are affected.
- Urgency
- Remediation is urgent as both vulnerabilities have been exploited as zero-days.
- Action
- Follow SonicWall's advisory and apply the recommended patches.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SMA1000
Get an email when a new SMA1000 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0239
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-15409Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 100% of all scored CVEs.
- Exploitation confirmedCVE-2026-15410Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15409 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15410 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] SonicWall SMA: Multiple vulnerabilitiescert-bund
- unknownSonicWall SMA1000 Series Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)cert-fr-alerte
- unknownexploitedMultiple vulnerabilities in Sonicwall Secure Mobile Access 1000 (July 15, 2026)cert-fr-avis
- criticalexploitedSonicWall security advisory (AV26-699) – Update 1cccs
- highexploitedCVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability ha…nvd
- criticalexploitedCVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Applianc…nvd
- criticalexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerabilitycisa-kev
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30