Two Zero-Day Vulnerabilities Patched in SonicWall SMA1000 Appliances (advisories.ncsc.nl)
- Two zero-day vulnerabilities patched in SonicWall SMA1000
- CVE-2026-15409: unauthenticated SSRF in Work Place interface
- CVE-2026-15410: post-auth code injection in AMC
"The Dutch National Cyber Security Centre (NCSC) reported two zero-day vulnerabilities in SonicWall SMA1000 appliances. CVE-2026-15409 is an unauthenticated Server-Side Request Forgery (SSRF) in the Work Place interface, allowing an attacker to make the device send requests to arbitrary locations. CVE-2026-15410 is a post-authentication code injection in the Appliance Management Console (AMC), enabling admin users to execute arbitrary OS commands. Both vulnerabilities have been exploited in the wild. The NCSC advises organizations to apply patches, check for indicators of compromise, and follow SonicWall's security advisory."
no comments yet.