Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
10.0
CVE-2026-15409KEVEXPLOITEDPATCHED
sonicwall · sma6210_firmware

CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A

Description

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Affected Products

VendorProductVersions
sonicwallsma6210_firmware12.4.3-03245, 12.5.0-02283

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallsmacert_advisory90%
sonicwallsma7210_firmwarecve_cpe95%
sonicwallsma8200vcve_cpe95%
sonicwallsma6210cve_cpe95%
sonicwallsma7210cve_cpe95%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008(vendor-advisory)

Related News (25 articles)

Tier C
Rapid7 Blog9d ago
Metasploit Wrap Up: Lot of summer shells and fit http profiles
→ No new info (linked only)
Tier D
BleepingComputer13d ago
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
→ No new info (linked only)
Tier D
The Hacker News20d ago
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
→ No new info (linked only)
Tier C
Rapid7 Blog24d ago
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
→ No new info (linked only)
Tier C
Rapid7 Blog26d ago
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
→ No new info (linked only)
Tier D
Help Net Security28d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier D
BleepingComputer32d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
→ No new info (linked only)
Tier C
Rapid7 Blog32d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
Help Net Security33d ago
SonicWall SMA zero-days were exploited weeks before disclosure
→ No new info (linked only)
Tier D
BleepingComputer34d ago
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
→ No new info (linked only)
Tier D
SecurityWeek34d ago
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
→ No new info (linked only)
Tier D
The Hacker News35d ago
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
→ No new info (linked only)
Tier D
Help Net Security35d ago
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
→ No new info (linked only)
Tier E
Hacker News39d ago
CVE-2026-15409: SonicWall SMA 1000 SSRF Zero-Day
→ No new info (linked only)
Tier C
Rapid7 Blog39d ago
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
→ No new info (linked only)
Tier B
BSI Advisories39d ago
[NEU] [kritisch] SonicWall SMA: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security39d ago
SonicWall SMA1000: Angriffe auf teils kritische Zero-Day-Lücken
→ No new info (linked only)
Tier D
The Hacker News40d ago
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
→ No new info (linked only)
Tier D
SecurityWeek40d ago
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans Sonicwall Secure Mobile Access 1000 (15 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans Secure Mobile Access (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-15409 | SonicWall SMA1000 up to 12.4.3-03434/12.5.0-02800 Work Place Interface server-side request forgery
→ No new info (linked only)
Tier E
Reddit r/cybersecurity40d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier D
BleepingComputer40d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier B
CCCS Canada40d ago
SonicWall security advisory (AV26-699) – Update 1
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
CWECWE-918
PublishedJul 14, 2026
Last enriched34d agov10
Tags
zero-dayCISA KEVwebsocketUTA0533root-accesspre-auth-bypassKnuckleBallOrangeTailSuo5state-sponsoredAPTCVE-2026-15410command-injectionwebshell-deploymentreverse-proxynginx-modificationcouchdb-enumeration/wsproxy-endpointsysCtrl.execRemoveHotfixproduct_uuidSou5ORANGETAILVolexity
Trending Score45
Source articles25
Independent12
Info Completeness12/14
Missing: epss, kev

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-66147
CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
Trending: 16
CRITICALCVE-2026-66145
CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
Trending: 16
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 15
HIGHCVE-2026-66149
CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 13
HIGHCVE-2026-66150
CVE-2026-66150: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 13

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, cweIds
Jul 14, 2026
Updated: affectedVersions, tags
Jul 14, 2026
Updated: affectedVersions
Jul 15, 2026
Updated: affectedVersions, exploitAvailable, activelyExploited
Jul 15, 2026
Updated: iocs
Jul 15, 2026
Updated: affectedVersions, tags
Jul 15, 2026
Updated: mitreAttack, tags
Jul 19, 2026
Updated: description, tags
Jul 20, 2026
Updated: affectedVersions, description, tags
Jul 20, 2026
Actively Exploited
Aug 4, 2026
Exploit Available
Aug 4, 2026
Patch Available
Aug 4, 2026

Version History

v10
Last enriched 34d ago
v10Tier D34d ago

Added patched versions 12.4.3-03453 and 12.5.0-02835, provided detailed technical exploitation chain including CVE-2026-15410 command injection, specific endpoint names (/wsproxy, sysCtrl.execRemoveHotfix), malware component details (Sou5 as reverse proxy, ORANGETAIL webshell functionality), and CouchDB enumeration technique.

affectedVersionsdescriptiontags
via BleepingComputer
v9Tier D34d ago

Added significant technical details about exploitation including custom malware (KnuckleBall, OrangeTail, Suo5) deployed post-compromise, confirmed exploitation timeline starting June 22, and attributed threat actor UTA0533 activity appears consistent with state-sponsored APT operations.

descriptiontags
via SecurityWeek
v8Tier D35d ago

Added significant technical detail about the pre-authentication /wsproxy bypass mechanism, confirmed active exploitation by UTA0533 threat actor since June 22, 2026, added MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) and T1133 (External Remote Services), and added threat actor and privilege escalation tags.

mitreAttacktags
via The Hacker News
v7Tier C39d ago

Updated description with technical details on exploitation and added new affected versions and tags.

affectedVersionstags
via Rapid7 Blog
v6Tier B39d ago

Added affected version 12.4.3-03453, updated patch availability to null, and included a new IOC URL.

iocs
via CERT-FR
v5Tier B39d ago

Updated affected versions to include 12.5.x prior to 12.5.0-02835 and 12.4.3-03453, and marked the vulnerability as actively exploited.

affectedVersionsexploitAvailableactivelyExploited
via CERT-FR
v4Tier D40d ago

Updated affected versions to include 6210, 7210, and 8200v, marked exploit as available, and noted active exploitation of the vulnerability.

affectedVersions
via SecurityWeek
v3Tier D40d ago

Updated affected versions, marked the vulnerability as actively exploited, added new patch version, and included indicators of compromise (IOCs) and relevant tags.

affectedVersionstags
via BleepingComputer
v2Tier B40d ago

Updated affected versions and marked the vulnerability as actively exploited.

affectedVersionscweIds
via CCCS Canada
v140d ago

Initial creation