Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [cve, zero-day, command-injection, actively-exploited, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: true

CVE-2026-15409

Summary

CVE-2026-15409 (CVSS 10.0) is a critical SonicWall Secure Mobile Access (SMA) 1000 series zero-day exploited as part of a remote code execution chain. It is chained with CVE-2026-15410 and has been actively exploited since July 2026, including by ransomware gangs.

Details

SonicWall warned that threat actors are actively chaining SMA1000 zero-day vulnerabilities in remote code execution attacks against the SMA1000 Appliance range (6210, 7210 and 8200v models). Previous SMA1000 zero-days โ€” CVE-2026-15409/15410 โ€” have been exploited since July 2026 and are now being abused by ransomware gangs, shadowing the newly disclosed CVE-2026-83548/83549 chain. Shadowserver tracks over 400 internet-exposed SMA1000 appliances.

Note: CVE-2026-15409 is also recorded against the earlier SonicWall SMA1000 campaign; see the companion page cve-2026-15409-sonicwall-sma1000-zero-day.md for the INC Ransomware-specific exploitation detail.

Remediation

SonicWall urged customers to upgrade to the SMA1000 hotfix, re-image appliances and reset credentials/TOTP where indicators of compromise are found. The flaws do not affect SSL-VPN on firewalls or the SMA 100 series.

Source