Summary of SonicWall SMA Vulnerabilities (CVE-2026-15409 and CVE-2026-15410)
Overview:
SonicWall recently disclosed two critical vulnerabilities affecting their Secure Mobile Access (SMA) appliances. These vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are classified as high severity due to the potential for remote code execution without authentication. Both vulnerabilities have been actively exploited by threat actors since May 2023.
Details:
- Vulnerability Type: Remote Code Execution (RCE)
- Severity Level: High
- Exploitation Status: Actively Exploited
Impact and Threat Actor Activity:
-
Initial Compromise:
- Attackers exploited the vulnerabilities to gain root access on affected SMA appliances.
- The attack vectors involved exploiting unpatched SMA versions, leading to full control over the devices.
-
Post-Compromise Activities:
- Once compromised, attackers used SMA appliances as internal footholds.
- They engaged in credential gathering and traffic capture activities.
- Mal
Read the full article at SOCRadar-? Cyber Intelligence Inc.
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





