THREAT OPS › Threat News › CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
<p><strong>SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.</strong></p><div class="blog-see-also"><h2>Key takeaways</h2><ol><li>CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code
Attributed threat actors
- AkiraG1024
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-15409cve
- CVE-2026-15410cve
- CVE-2019-7481cve
- CVE-2019-7483cve
- CVE-2021-20016cve
- CVE-2021-20038cve
- CVE-2025-23006cve
- CVE-2024-40766cve
- CVE-2025-40602cve
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008url
- https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watchurl