CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
2026-07-15T20:52:28Z•1200b420c11b27d16553086105c6be77c0046ab11929a56b86e1a26d8b7c8a20
SMA 1000SSRFfederal-guidancein-the-wild exploitationindicators of compromiselarge-scale disclosuremicrosoft patch tuesdaypatch availableremote code executionsonicwallvulnerability managementzero-day
What happened
Tenable reports multiple high-impact security updates: SonicWall disclosed two exploited zero-days in SMA 1000 appliances (CVE-2026-15409 — SSRF, CVSSv3 10 — and CVE-2026-15410 — RCE) that may be chained for unauthenticated remote code execution; SonicWall confirmed in-the-wild exploitation and published patches and IOCs with urgent remediation guidance. Microsoft’s July 2026 Patch Tuesday addressed a record 569 CVEs, including three zero-days (two exploited in the wild, e.g. CVE-2026-56155 and CVE-2026-56164); organizations should prioritize patching high/critical updates. The collection also
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 1200b420c11b27d16553086105c6be77c0046ab11929a56b86e1a26d8b7c8a20
- Enrichment time
- 2026-07-15T20:52:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.