type: cve ยท created: 2026-07-19 ยท updated: 2026-08-18 ยท tags: [cve, vulnerability, sonicwall, vpn, zero-day, cvss-10] ยท confidence: high ยท severity: critical ยท affected_sectors: [] ยท au_impact: true
CVE-2026-15409 & CVE-2026-15410 โ SonicWall SMA Zero-Day Chain
CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) are zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.
- Discovered by: Volexity (incident response investigation, early July 2026)
- Threat actor: Uta0533 (previously undocumented, tracked by Volexity)
- Exploitation window: Active since at least June 22, 2026, before public disclosure
- Impact: Chained to facilitate arbitrary command execution and full device takeover
- Patches: Released by SonicWall mid-July 2026
Technical Details
CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) can be chained together. The attacker gains root access to affected SMA 1000 series appliances without authentication.
References
- The Hacker News reporting (2026-07-19)
- Volexity analysis by Sean Koessel and Steven Adair
Provenance
2026-07-19: First reported by Volexity; covered by The Hacker News and included in Cyber Digest 2026-07-20.