Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Last week, SonicWall warned that threat actors were actively exploiting two previously undisclosed vulnerabilities in an exploit chain that affected SMA1000 Secure Mobile Access appliances.
The flaws, tracked as CVE-2026-15409, a critical server-side request forgery (SSRF) vulnerability, and CVE-2026-15410, a high-severity command injection flaw, affect SMA1000 6210, 7210, and 8200v appliances.
SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately.
While SonicWall confirmed that the flaws were exploited as zero-days, they did not disclose details on how the attackers were compromising the devices.








