Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SonicWall SMA1000 vulnerability, tracked as CVE-2026-15409 , to its Known Exploited Vulnerabilities (KEV) catalog after confirming exploitation in real-world attacks. The flaw, a maximum-severity server-side request forgery (SSRF) bug, was weaponized as a zero-day alongside a second vulnerability affecting SonicWall secure remote-access appliances. CVE-2026-15409 carries a CVSS score of 10. 0 and affects the SonicWall SMA1000 Appliance Workplace interface . Classified as CWE-918, the issue enables a remote, unauthenticated attacker to coerce a vulnerable appliance into making requests to unintended locations.

AwsCVE-2026-15409CVE-2026-15410
·CyberPress
Read →
Breaches & Ransomware
Emerging1 src

CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware

The U. S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410 , are being exploited in ransomware attacks and have been added to its KEV catalog. CISA has also marked both vulnerabilities as known to be used in ransomware campaigns, making immediate remediation essential for organizations using exposed SMA1000 systems. SonicWall disclosed the vulnerabilities on July 14, 2026, under advisory SNWLID-2026-0008 . The company said its Product Security Incident Response Team investigated multiple cases of active exploitation and urged customers to install the available platform hotfixes as soon as possible. The affected products include SMA 6210, SMA 7210, and SMA 8200v appliances running vulnerable platform-hotfix releases 12. 4. 3 or 12. 5. 0.

CVE-2026-15409CVE-2026-15410
·Cyber Security News
Read →