CRITICAL ⚡ MUST-KNOW
Two SonicWall SMA 1000 Zero-Days Under Active Exploitation
SonicWall has warned of active exploitation of two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances. One of them, CVE-2026-15409, is a server-side request forgery (SSRF) flaw with a CVSS score of 10.0 that a remote, unauthenticated attacker could exploit, potentially leading to arbitrary admin command execution. Organizations running SMA 1000 appliances should patch immediately.