Post
CRITICAL ⚡ MUST-KNOW

Two SonicWall SMA 1000 Zero-Days Under Active Exploitation

· zero-day · ssrf · cve · vulnerability

SonicWall has warned of active exploitation of two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances. One of them, CVE-2026-15409, is a server-side request forgery (SSRF) flaw with a CVSS score of 10.0 that a remote, unauthenticated attacker could exploit, potentially leading to arbitrary admin command execution. Organizations running SMA 1000 appliances should patch immediately.