CuraSec

Act archived

SonicWall SMA1000 zero-days actively exploited, patches available

2026-07-15 12:11 UTC · BleepingComputer · read the source ↗ #zero-day#vpn-appliance#cisa-kev
  • Engineer — Act: Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation — patch SMA1000 appliances to the latest firmware immediately and audit access logs for signs of pre-patch compromise.
  • SOC/IR — Act: Edge appliance exploitation means assume-breach posture is warranted — sweep for lateral movement or credential harvesting activity originating from SMA1000 IPs since the zero-day window, and hunt for post-exploitation behavior in downstream systems.
  • Leader — Act: Actively exploited VPN appliances are a board-level exposure; confirm whether your organization runs SMA1000, verify patching status with the engineering team, and prepare a brief in case the incident becomes public.
  • Signals: CVE-2026-15409 — CISA KEV: listed, EPSS n/a, public PoC on GitHub, reported by 2 collected sources · CVE-2026-15410 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.