SonicWall SMA 1000 VPN zero-days actively exploited, chained for full appliance takeover
Rapid7 uncovered two zero-day flaws in SonicWall SMA 1000 VPN appliances being exploited together to fully hijack the devices. One is an unauthenticated maximum-severity SSRF, the other lets an admin run OS commands. CISA has set a federal patching deadline of July 17.
Security firm Rapid7 discovered two zero-day vulnerabilities in internet-facing SonicWall SMA 1000 VPN appliances under active exploitation. CVE-2026-15409 is an unauthenticated server-side request forgery flaw rated 10.0 out of 10; CVE-2026-15410 lets an authenticated administrator run arbitrary OS commands. Attackers chain both to seize complete control of the network-edge device. Rapid7 reports targeted exploitation since at least late last month, SonicWall confirmed multiple incidents, and CISA added both to its Known Exploited Vulnerabilities catalog with a federal patch deadline of July 17. SonicWall urges customers to install the emergency hotfix immediately.