SonicWall Security Updates – 15 July 2026

SonicWall has released security updates to fix several vulnerabilities affecting SonicWall SMA1000 Series Appliances.

The addressed vulnerabilities could allow the remote attacker to perform a serverside request forgery (SSRF) attack or execute arbitrary operating system (OS) commands, potentially leading to the complete compromise of the affected system.

The addressed vulnerabilities:

1. SonicWall SMA1000 Server-Side Request Forgery (SSRF) Vulnerability (CVE- 2026-15409):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Server-Side Request Forgery

2. SonicWall SMA1000 Improper Control of Generation of Code Vulnerability (CVE-2026-15410):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Remote Code Execution

It should be highlighted that SonicWall PSIRT is aware that the vulnerabilities “CVE- 2026-15409” and “CVE-2026-15409” are being actively exploited in the wild.

Vulnerabilities
  • CVE-2026-15409
  • CVE-2026-15410
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SonicWall Security Advisory

References