Published Monday, July 20, 2026 at 02:44 AM PT

BLUF: Volexity has confirmed active exploitation of zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances. Attackers are bypassing multi-factor authentication (MFA) and gaining unauthorized access to enterprise networks. Organizations operating SonicWall SMA 1000 devices should assume compromise and apply vendor patches immediately. CVE-2026-15409 and CVE-2026-15410 are confirmed affected.
DETAILS:
- Active exploitation confirmed in the wild โ Volexity and Huntress (blue team) have independently verified attackers are actively exploiting these vulnerabilities against SonicWall customers in real-time operations
- MFA bypass capability โ Attackers can circumvent multi-factor authentication protections, indicating authentication/session handling flaws in affected appliances
- Two zero-day CVEs identified โ CVE-2026-15409 and CVE-2026-15410 are the confirmed vulnerable components; SonicWall has issued urgent patch guidance
- SMA 1000 appliances targeted โ Specific focus on SonicWall Secure Mobile Access (SMA) 1000 series; scope of other SonicWall VPN models under assessment
- Exploitation timeline uncertain โ Initial compromise window unknown; organizations cannot determine how long devices may have been exposed
IMPACT:
- Scope: All organizations deploying SonicWall SMA 1000 appliances as remote access VPN gateways
- Access level: Successful exploitation grants attackers network ingress equivalent to authenticated VPN user; potential for lateral movement, data exfiltration, and persistence
- Affected systems: Enterprise networks relying on these appliances for secure remote workforce access
RECOMMENDED ACTIONS:
- Immediate: Apply SonicWall security patches for CVE-2026-15409 and CVE-2026-15410 to all SMA 1000 appliances
- Urgent: Review VPN access logs for anomalous authentication patterns, session hijacking, or unauthorized administrative access
- Assume compromise: Treat all VPN sessions as potentially compromised until patching is complete; monitor for lateral movement indicators
- Escalate: Notify security operations and incident response teams; coordinate with SonicWall support for patch deployment assistance
SOURCES:
- Volexity threat research (primary disclosure)
- Huntress Labs (independent confirmation)
- SonicWall vendor advisory
- SecurityAffairs, CyberScoop, Help Net Security, SecurityWeek reporting
