CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

SonicWall security advisory (AV26-699) – Update 1

criticalknown exploitedpublic exploitCVE-2026-15409CVE-2026-15410
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-699 Date: July 14, 2026 On July 14, 2026, SonicWall published a security advisory to address critical vulnerabilities in the following products: SMA1000 Models (6210, 7210 & 8200v) - version 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 ( platform-hotfix ) SMA1000 Models (6210, 7210 & 8200v) - version 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 ( platform-hotfix ) SonicWall indicates that CVE-2026-15409 and CVE-2026-15410 are being exploited. Update 1 On July 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-15409 and CVE-2026-15410 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities SonicWall Security Advisories CISA KEV: CVE-2026-15409 CISA KEV: CVE-2026-15410

CSIRTS triage

vendor: SonicWallproduct: SMA1000Remote code executionServer-side request forgeryaffected: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, 12.5.0-02800
What
Multiple critical vulnerabilities have been identified in the SMA1000 series appliances.
Who is affected
SMA1000 series appliance users with the specified versions are affected.
Urgency
Remediation is urgent due to active exploitation of the vulnerabilities.
Action
Users should apply the necessary updates as indicated in the advisory.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SMA1000

Get an email when a new SMA1000 advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-14
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-699

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-15409coverage & exploitation statusNVD · CVE.org
CVE-2026-15410coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security