LIVE · cybersecurity feed
Live wire
vendor4 exploited in the wild

Sonicwall

4 CVEs published in the last four months and 7 stories. Exploited flaws first.

Critical2
High2
Medium0
Exploited (KEV)4

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-15409exploited10criticalsma6210 firmwareA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interfa53d ago
CVE-2026-83548exploited10criticalsma8200vA Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended 4d ago
CVE-2026-83549exploited7.8highsma8200vPost-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul4d ago
CVE-2026-15410exploited7.2highsma6210 firmwarePost-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in53d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-15409exploited10criticalsma6210 firmwareA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interfa53d ago
CVE-2026-83548exploited10criticalsma8200vA Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended 4d ago
CVE-2026-83549exploited7.8highsma8200vPost-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul4d ago
CVE-2026-15410exploited7.2highsma6210 firmwarePost-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in53d ago

Filter the full tracker by Sonicwall

Our coverage of Sonicwall

vulnerabilityhigh

Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop.

vulnerability

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

sonicwallcritical

Ransomware Gangs Exploit SonicWall SMA1000 Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting two vulnerabilities in SonicWall's SMA1000 series appliances. These flaws, which have already been patched, include a critical server-side request forgery (SSRF) vulnerability. The exploitation is linked to ransomware attacks.

ransomware

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

vulnerability

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]

CVE-2026-15409critical

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

ransomwarecritical

Inc Ransomware Exploits SonicWall SMA Zero-Days

The Inc ransomware group is actively exploiting two zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances. Successful exploitation grants attackers root-level control over the affected devices, enabling further malicious activities.