THREAT OPS › Threat News › Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
<h2>Overview</h2><p style="direction: ltr;"><span style="font-size: undefined;">On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span style="font-size: undefined;">published</span></a><span style="font-size: undefined;"> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances,
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-15409cve
- CVE-2026-15410cve
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008url
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITWurl
- https://192.168.181.46:8443url
- https://192.168.181.46:8443/rollbackConfirm.actionurl
- 152.0.0.0ipv4
- 45.131.194.0ipv4
- 45.146.54.0ipv4
- 63.135.161.0ipv4
- 173.239.211.0ipv4
- 193.37.32.179ipv4
- 193.37.32.214ipv4
- 216.73.163.151ipv4
- 216.73.163.158ipv4
- 45.131.194.0/24cidr
- 45.146.54.0/24cidr
- 63.135.161.0/24cidr
- 173.239.211.0/24cidr