vuln-advisorytrade-pressNewsThe Broadside1 min read

CISA adds exploited SonicWall SMA1000 zero-days to KEV

SMA1000 operators need to upgrade, check SonicWall’s indicators of compromise, and treat suspicious activity as a live intrusion.


TL;DR

SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 for SMA1000 appliances Tuesday, and CISA added both to the Known Exploited Vulnerabilities catalog the same day. Rapid7 told CyberScoop exploitation began June 22 and likely aimed at ransomware. SonicWall says fewer than 5,000 SMA1000 units sit within its roughly one million monitored sensors, but also warned customers that patching alone is insufficient.

For SMA1000 operators, the work starts with the upgrade and then moves immediately into evidence review. SonicWall released fixes Tuesday for CVE-2026-15409, a max-severity flaw that can let attackers make authenticated requests, and CVE-2026-15410, a 7.2-rated authenticated command injection vulnerability. SonicWall confirmed to CyberScoop that the two flaws have been chained together. VulnCheck’s Landon Rice put the operational result plainly: chained exploitation can take an attacker from zero access to complete compromise of the affected appliance.

The timing is ugly because this was not a theoretical advisory. Rapid7 researchers told CyberScoop they first saw exploitation on June 22 and said the observed activity likely pointed toward ransomware, although Rapid7 said it prevented exfiltration and encryption in the cases it handled. SonicWall has not said when it discovered the issues, when exploitation first began, how many customers were hit, or whether it attributes the activity to a known group.

CISA’s Known Exploited Vulnerabilities listing gives federal civilian agencies a binding remediation clock and gives everyone else the useful part of the signal: treat the appliance as exposed. SonicWall says support staff are helping customers investigate suspicious activity, and it shared indicators of compromise for hunting. The practical sequence is upgrade, hunt, and escalate anything suspicious as a possible intrusion, because the vendor itself says patching by itself is not enough.


Published ·Deep Fathom