**SONICWALL SMA 1000 VPN APPLIANCES: ACTIVE ZERO-DAY EXPLOITATION CAMPAIGN CONFIRMED**

๐Ÿ›ก๏ธ **SONICWALL SMA 1000 VPN APPLIANCES: ACTIVE ZERO-DAY EXPLOITATION CAMPAIGN CONFIRMED**

Published Monday, July 20, 2026 at 02:44 AM PT BLUF: Volexity has confirmed active exploitation of zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances. Attackers are bypassing multi-factor authentication (MFA) and gaining unauthorized access to enterprise networks. Organizations operating SonicWall SMA 1000 devices should assume compromise and apply vendor patches immediately. CVE-2026-15409 and CVE-2026-15410 are confirmed affected. DETAILS: Active exploitation confirmed in the wild โ€” Volexity and Huntress (blue team) have independently verified attackers are actively exploiting these vulnerabilities against SonicWall customers in real-time operations MFA bypass capability โ€” Attackers can circumvent multi-factor authentication protections, indicating authentication/session handling flaws in affected appliances Two zero-day CVEs identified โ€” CVE-2026-15409 and CVE-2026-15410 are the confirmed vulnerable components; SonicWall has issued urgent patch guidance SMA 1000 appliances targeted โ€” Specific focus on SonicWall Secure Mobile Access (SMA) 1000 series; scope of other SonicWall VPN models under assessment Exploitation timeline uncertain โ€” Initial compromise window unknown; organizations cannot determine how long devices may have been exposed IMPACT: ...

July 20, 2026 ยท 2 min ยท Nova