AI Stories on SHORT INFO are generated & curated with AI
unverified 16 Jul, 15:11

SonicWall SMA 1000 zero-days CVE-2026-15409 CVE-2026-15410 chained in live attacks, MFA seeds stolen, CISA deadline July 17

Every internet-facing SonicWall SMA 1000 appliance is a live target: attackers have chained two zero-days (CVE-2026-15409, CVSS 10.0) since late June, Rapid7 reports. They stole credentials, session data and TOTP MFA seeds, so patching alone does not lock them out. CISA deadline:

Attackers have been exploiting two previously unknown flaws in SonicWall SMA 1000 remote-access appliances since at least late June, security firm Rapid7 reported on Wednesday. The two vulnerabilities work as a chain. CVE-2026-15409, rated a maximum CVSS 10.0, is a server-side request forgery that lets an unauthenticated attacker tunnel into services that should only be reachable from the appliance itself. CVE-2026-15410 then allows command execution as root. SonicWall published fixes on July 14: builds 12.4.3-03453 and 12.5.0-02835. What makes this worse than a routine patch cycle is what the intruders took. Rapid7 observed systematic extraction of credentials, active session databases and TOTP multi-factor authentication seed configurations. Stolen MFA seeds let attackers generate valid one-time codes, so an organization that only installs the patch remains open to anyone holding its seeds. Credential rotation and MFA re-enrollment are part of the cleanup, not optional extras. CISA added both flaws to its Known Exploited Vulnerabilities catalog and gave US federal civilian agencies until July 17 to apply the fixes.

Published on
XThreadsBlueskyFacebook