CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

2026-07-15T20:52:28Z1200b420c11b27d16553086105c6be77c0046ab11929a56b86e1a26d8b7c8a20
SMA 1000SSRFfederal-guidancein-the-wild exploitationindicators of compromiselarge-scale disclosuremicrosoft patch tuesdaypatch availableremote code executionsonicwallvulnerability managementzero-day

What happened

Tenable reports multiple high-impact security updates: SonicWall disclosed two exploited zero-days in SMA 1000 appliances (CVE-2026-15409 — SSRF, CVSSv3 10 — and CVE-2026-15410 — RCE) that may be chained for unauthenticated remote code execution; SonicWall confirmed in-the-wild exploitation and published patches and IOCs with urgent remediation guidance. Microsoft’s July 2026 Patch Tuesday addressed a record 569 CVEs, including three zero-days (two exploited in the wild, e.g. CVE-2026-56155 and CVE-2026-56164); organizations should prioritize patching high/critical updates. The collection also

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
1200b420c11b27d16553086105c6be77c0046ab11929a56b86e1a26d8b7c8a20
Enrichment time
2026-07-15T20:52:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.