SonicWall security advisory (AV26-699) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-699 Date: July 14, 2026 On July 14, 2026, SonicWall published a security advisory to address critical vulnerabilities in the following products: SMA1000 Models (6210, 7210 & 8200v) - version 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 ( platform-hotfix ) SMA1000 Models (6210, 7210 & 8200v) - version 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 ( platform-hotfix ) SonicWall indicates that CVE-2026-15409 and CVE-2026-15410 are being exploited. Update 1 On July 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-15409 and CVE-2026-15410 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities SonicWall Security Advisories CISA KEV: CVE-2026-15409 CISA KEV: CVE-2026-15410
CSIRTS triage
- What
- Multiple critical vulnerabilities have been identified in the SMA1000 series appliances.
- Who is affected
- SMA1000 series appliance users with the specified versions are affected.
- Urgency
- Remediation is urgent due to active exploitation of the vulnerabilities.
- Action
- Users should apply the necessary updates as indicated in the advisory.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SMA1000
Get an email when a new SMA1000 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-699
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-15409Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 100% of all scored CVEs.
- Exploitation confirmedCVE-2026-15410Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15409 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15410 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] SonicWall SMA: Multiple vulnerabilitiescert-bund
- unknownexploitedNCSC-2026-0239 [1.00] [H/H] Zero-Day vulnerabilities fixed in SonicWall SMA1000ncsc-nl
- unknownSonicWall SMA1000 Series Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)cert-fr-alerte
- unknownexploitedMultiple vulnerabilities in Sonicwall Secure Mobile Access 1000 (July 15, 2026)cert-fr-avis
- highexploitedCVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability ha…nvd
- criticalexploitedCVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Applianc…nvd
- criticalexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa-kev
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30