Find notable cyber news and cases, enriched with sources, timelines, and signals.

SonicWall SMA1000 command injection flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

SonicWall SMA1000 devices are exposed to an actively exploited zero-day chain involving CVE-2026-83548 and CVE-2026-83549, creating remote code execution risk on affected appliances. The flaws affect SMA1000 6210, 7210, and 8200v models and were tied to hotfix remediation guidance.

Related Happenings

SonicWall SMA1000 hotfix advisory

Advisory/Mitigation
H score46 First: 02.09.2026 09:39 Last: 02.09.2026 09:39 Sources 1

How related: "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company warned in a Tuesday advisory.

About this happening: SonicWall told SMA1000 customers to install the latest hotfix immediately after confirming active exploitation of two zero-days that can enable remote code execution...

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave
H score24 First: 03.08.2026 13:39 Last: 03.08.2026 13:39 Sources 1

About this happening: SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...

INC Ransomware campaign expands across multiple victims

Campaign
H score43 First: 03.08.2026 13:39 Last: 03.08.2026 13:39 Sources 1

About this happening: The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...

SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)

Vulnerability
H score48 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

About this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...

Latest development: 03.08.2026 13:39

SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.

Timeline

  1. 02.09.2026 09:39 2 articles · 2h ago

    SonicWall warns of actively exploited SMA1000 zero-day command injection chain

    Initial Disclosure

    SonicWall warned that threat actors are chaining CVE-2026-83548 and CVE-2026-83549 against SMA1000 6210, 7210, and 8200v appliances to achieve remote code execution, and said PSIRT has investigated a case indicating active exploitation. The company urged customers to install the latest hotfix version and, if indicators of compromise are found, to re-image appliances, change all user and administrator passwords, and reset TOTP tokens.

    Show sources