SonicWall SMA1000 Series Products Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities exist in SonicWall SMA1000 Series Products that have been exploited.
- Who is affected
- All deployments of SMA1000 Series Products are affected by these vulnerabilities.
- Urgency
- Immediate remediation is necessary due to active exploitation of the vulnerabilities.
- Action
- Update to the latest firmware version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SMA1000 Series
Get an email when a new SMA1000 Series advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/sonicwall-sma1000-series-products-multiple-vulnerabilities_20260715
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2026-15409EPSS puts this in the most-targeted tier (78.4% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2026-15410EPSS puts this in the most-targeted tier (76.3% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15409 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15410 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] SonicWall SMA: Multiple vulnerabilitiescert-bund
- unknownexploitedNCSC-2026-0239 [1.00] [H/H] Zero-Day vulnerabilities fixed in SonicWall SMA1000ncsc-nl
- unknownexploitedMultiple vulnerabilities in Sonicwall Secure Mobile Access 1000 (July 15, 2026)cert-fr-avis
- unknownexploitedMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)cert-fr-alerte
- criticalexploitedSonicWall security advisory (AV26-699) – Update 1cccs
- highexploitedCVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability ha…nvd
- criticalexploitedCVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Applianc…nvd
- criticalexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerabilitycisa-kev
More from HKCERT Security Bulletins
- unknownGoogle Chrome Multiple Vulnerabilities2026-07-30
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownNode.js Multiple Vulnerabilities2026-07-30
- unknownXen Multiple Vulnerabilities2026-07-30