[NEW] [critical] SonicWall SMA: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in SonicWall SMA to bypass security measures and execute arbitrary operating system commands on the affected system.
CSIRTS triage
- What
- Multiple vulnerabilities allow a remote, anonymous attacker to bypass security measures and execute arbitrary operating system commands.
- Who is affected
- Deployments of SonicWall SMA are affected.
- Urgency
- Remediation is urgent due to the critical severity and confirmed exploitation.
- Action
- Apply the latest patches provided by SonicWall.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SMA
Get an email when a new SMA advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2346
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2026-15409EPSS puts this in the most-targeted tier (78.4% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2026-15410EPSS puts this in the most-targeted tier (76.3% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15409 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15410 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0239 [1.00] [H/H] Zero-Day vulnerabilities fixed in SonicWall SMA1000ncsc-nl
- unknownSonicWall SMA1000 Series Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)cert-fr-alerte
- unknownexploitedMultiple vulnerabilities in Sonicwall Secure Mobile Access 1000 (July 15, 2026)cert-fr-avis
- criticalexploitedSonicWall security advisory (AV26-699) – Update 1cccs
- highexploitedCVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability ha…nvd
- criticalexploitedCVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Applianc…nvd
- criticalexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerabilitycisa-kev
Recent advisories for SonicWall SMA
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedCVE-2021-20038: SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerabilitycisa-kev · 2022-01-28
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31