The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being exploited in ransomware attacks and have been added to its KEV catalog. CISA has also marked both vulnerabilities as known to be used in ransomware campaigns, urging organizations using exposed SMA1000 systems to immediately remediate the situation. SonicWall disclosed these vulnerabilities on July 14, 2026, under advisory SNWLID-2026-0008, and stated that its Product Security Incident Response Team investigated multiple cases of active exploitation, urging customers to install available platform hotfixes as soon as possible.
The impacted products are the SMA 6210, SMA 7210, and SMA 8200v appliances running vulnerable platform-hotfix releases 12.4.3 or 12.5.0.
The flaw could cause the appliance to send requests to unauthorized internal or external locations, potentially turning an internet-facing remote-access device into a gateway for services not intended for public access. A successful compromise could enable attackers to steal credentials, intercept session information, establish persistence, move into internal systems, and prepare for a ransomware deployment. There's no workaround; patching is the primary defense.
SonicWall advised defenders to review extraweb_access.log for unusual requests involving /api/login, /api/logout, or /wsproxy, particularly suspicious host parameters and HTTP 101 responses. If indicators of compromise are detected, SonicWall advises re-imaging physical appliances or redeploying virtual ones, changing all user and administrator passwords, and resetting TOTP tokens.












