SonicWall disclosed two zero-day vulnerabilities in its SMA1000 secure remote access appliances this week, and the U.S. Cybersecurity and Infrastructure Security Agency moved fast: both flaws are now on the agency’s Known Exploited Vulnerabilities catalog, with a remediation deadline of July 17 for federal agencies.

The more severe of the pair, CVE-2026-15409, is a CVSS 10.0 server side request forgery that lets an unauthenticated attacker force an SMA1000 appliance into making requests on the attacker’s behalf, no valid login required. The second, CVE-2026-15410 (CVSS 7.2), is a post authentication code injection flaw that lets an already logged in administrator run arbitrary operating system commands. Together the two give an attacker a path from zero access toward full appliance control. SonicWall’s advisory lists patched platform hotfix builds for the affected 6210, 7210, and 8200v models.

The pattern matters more than the single product. SMA1000, like the NetScaler and Adobe ColdFusion flaws CyberTech covered earlier this month, is a remote access edge appliance, the exact category attackers have consistently targeted first because it sits internet facing and, once compromised, hands over a foothold inside the perimeter. The gap between disclosure, CISA’s KEV addition, and a federal remediation deadline is now measured in days for this appliance class, not weeks. Security teams running SMA1000 in production should treat the patch as a same week action rather than queue it behind routine change control.

Source: SonicWall PSIRT