Published Monday, July 20, 2026 at 02:44 AM PT

<strong>SONICWALL SMA 1000 VPN APPLIANCES: ACTIVE ZERO-DAY EXPLOITATION CAMPAIGN CONFIRMED</strong>

BLUF: Volexity has confirmed active exploitation of zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances. Attackers are bypassing multi-factor authentication (MFA) and gaining unauthorized access to enterprise networks. Organizations operating SonicWall SMA 1000 devices should assume compromise and apply vendor patches immediately. CVE-2026-15409 and CVE-2026-15410 are confirmed affected.


DETAILS:

  • Active exploitation confirmed in the wild โ€” Volexity and Huntress (blue team) have independently verified attackers are actively exploiting these vulnerabilities against SonicWall customers in real-time operations
  • MFA bypass capability โ€” Attackers can circumvent multi-factor authentication protections, indicating authentication/session handling flaws in affected appliances
  • Two zero-day CVEs identified โ€” CVE-2026-15409 and CVE-2026-15410 are the confirmed vulnerable components; SonicWall has issued urgent patch guidance
  • SMA 1000 appliances targeted โ€” Specific focus on SonicWall Secure Mobile Access (SMA) 1000 series; scope of other SonicWall VPN models under assessment
  • Exploitation timeline uncertain โ€” Initial compromise window unknown; organizations cannot determine how long devices may have been exposed

IMPACT:

  • Scope: All organizations deploying SonicWall SMA 1000 appliances as remote access VPN gateways
  • Access level: Successful exploitation grants attackers network ingress equivalent to authenticated VPN user; potential for lateral movement, data exfiltration, and persistence
  • Affected systems: Enterprise networks relying on these appliances for secure remote workforce access

RECOMMENDED ACTIONS:

  1. Immediate: Apply SonicWall security patches for CVE-2026-15409 and CVE-2026-15410 to all SMA 1000 appliances
  2. Urgent: Review VPN access logs for anomalous authentication patterns, session hijacking, or unauthorized administrative access
  3. Assume compromise: Treat all VPN sessions as potentially compromised until patching is complete; monitor for lateral movement indicators
  4. Escalate: Notify security operations and incident response teams; coordinate with SonicWall support for patch deployment assistance

SOURCES:

  • Volexity threat research (primary disclosure)
  • Huntress Labs (independent confirmation)
  • SonicWall vendor advisory
  • SecurityAffairs, CyberScoop, Help Net Security, SecurityWeek reporting