Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3752 articles · 207518 vulns · 36/41 feeds (7d)
← Back to list
10.0
CVE-2026-15409KEVEXPLOITEDPATCHED
sonicwall · sma6210_firmware

CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A

Description

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Affected Products

VendorProductVersions
sonicwallsma6210_firmware12.4.3-03245, 12.5.0-02283

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallsmacert_advisory90%
sonicwallsma7210_firmwarecve_cpe95%
sonicwallsma8200vcve_cpe95%
sonicwallsma6210cve_cpe95%
sonicwallsma7210cve_cpe95%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008(vendor-advisory)

Related News (25 articles)

Tier C
Rapid7 Blog18d ago
Metasploit Wrap Up: Lot of summer shells and fit http profiles
→ No new info (linked only)
Tier D
BleepingComputer22d ago
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
→ No new info (linked only)
Tier D
The Hacker News29d ago
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
→ No new info (linked only)
Tier C
Rapid7 Blog33d ago
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
→ No new info (linked only)
Tier C
Rapid7 Blog35d ago
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
→ No new info (linked only)
Tier D
Help Net Security38d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier D
BleepingComputer41d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
→ No new info (linked only)
Tier C
Rapid7 Blog41d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
Help Net Security42d ago
SonicWall SMA zero-days were exploited weeks before disclosure
→ No new info (linked only)
Tier D
BleepingComputer43d ago
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
→ No new info (linked only)
Tier D
SecurityWeek43d ago
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
→ No new info (linked only)
Tier D
The Hacker News44d ago
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
→ No new info (linked only)
Tier D
Help Net Security45d ago
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
→ No new info (linked only)
Tier E
Hacker News48d ago
CVE-2026-15409: SonicWall SMA 1000 SSRF Zero-Day
→ No new info (linked only)
Tier C
Rapid7 Blog48d ago
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
→ No new info (linked only)
Tier B
BSI Advisories48d ago
[NEU] [kritisch] SonicWall SMA: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security48d ago
SonicWall SMA1000: Angriffe auf teils kritische Zero-Day-Lücken
→ No new info (linked only)
Tier D
The Hacker News49d ago
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
→ No new info (linked only)
Tier D
SecurityWeek49d ago
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
→ No new info (linked only)
Tier B
CERT-FR49d ago
Multiples vulnérabilités dans Sonicwall Secure Mobile Access 1000 (15 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR49d ago
Multiples vulnérabilités dans Secure Mobile Access (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB49d ago
CVE-2026-15409 | SonicWall SMA1000 up to 12.4.3-03434/12.5.0-02800 Work Place Interface server-side request forgery
→ No new info (linked only)
Tier E
Reddit r/cybersecurity49d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier D
BleepingComputer49d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier B
CCCS Canada49d ago
SonicWall security advisory (AV26-699) – Update 1
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
CWECWE-918
PublishedJul 14, 2026
Last enriched43d agov10
Tags
zero-dayCISA KEVwebsocketUTA0533root-accesspre-auth-bypassKnuckleBallOrangeTailSuo5state-sponsoredAPTCVE-2026-15410command-injectionwebshell-deploymentreverse-proxynginx-modificationcouchdb-enumeration/wsproxy-endpointsysCtrl.execRemoveHotfixproduct_uuidSou5ORANGETAILVolexity
Trending Score13
Source articles25
Independent12
Info Completeness12/14
Missing: epss, kev

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-83548EXPKEV
CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
Trending: 119
HIGHCVE-2026-83549EXPKEV
CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Trending: 116
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 107
HIGHCVE-2026-66152
CVE-2026-66152: A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to
Trending: 17
HIGHCVE-2026-66153
CVE-2026-66153: The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows
Trending: 17

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, cweIds
Jul 14, 2026
Updated: affectedVersions, tags
Jul 14, 2026
Updated: affectedVersions
Jul 15, 2026
Updated: affectedVersions, exploitAvailable, activelyExploited
Jul 15, 2026
Updated: iocs
Jul 15, 2026
Updated: affectedVersions, tags
Jul 15, 2026
Updated: mitreAttack, tags
Jul 19, 2026
Updated: description, tags
Jul 20, 2026
Updated: affectedVersions, description, tags
Jul 20, 2026
Actively Exploited
Aug 4, 2026
Exploit Available
Aug 4, 2026
Patch Available
Aug 4, 2026

Version History

v10
Last enriched 43d ago
v10Tier D43d ago

Added patched versions 12.4.3-03453 and 12.5.0-02835, provided detailed technical exploitation chain including CVE-2026-15410 command injection, specific endpoint names (/wsproxy, sysCtrl.execRemoveHotfix), malware component details (Sou5 as reverse proxy, ORANGETAIL webshell functionality), and CouchDB enumeration technique.

affectedVersionsdescriptiontags
via BleepingComputer
v9Tier D43d ago

Added significant technical details about exploitation including custom malware (KnuckleBall, OrangeTail, Suo5) deployed post-compromise, confirmed exploitation timeline starting June 22, and attributed threat actor UTA0533 activity appears consistent with state-sponsored APT operations.

descriptiontags
via SecurityWeek
v8Tier D44d ago

Added significant technical detail about the pre-authentication /wsproxy bypass mechanism, confirmed active exploitation by UTA0533 threat actor since June 22, 2026, added MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) and T1133 (External Remote Services), and added threat actor and privilege escalation tags.

mitreAttacktags
via The Hacker News
v7Tier C48d ago

Updated description with technical details on exploitation and added new affected versions and tags.

affectedVersionstags
via Rapid7 Blog
v6Tier B48d ago

Added affected version 12.4.3-03453, updated patch availability to null, and included a new IOC URL.

iocs
via CERT-FR
v5Tier B48d ago

Updated affected versions to include 12.5.x prior to 12.5.0-02835 and 12.4.3-03453, and marked the vulnerability as actively exploited.

affectedVersionsexploitAvailableactivelyExploited
via CERT-FR
v4Tier D49d ago

Updated affected versions to include 6210, 7210, and 8200v, marked exploit as available, and noted active exploitation of the vulnerability.

affectedVersions
via SecurityWeek
v3Tier D49d ago

Updated affected versions, marked the vulnerability as actively exploited, added new patch version, and included indicators of compromise (IOCs) and relevant tags.

affectedVersionstags
via BleepingComputer
v2Tier B49d ago

Updated affected versions and marked the vulnerability as actively exploited.

affectedVersionscweIds
via CCCS Canada
v149d ago

Initial creation