Rapid7 Caught Hackers Hitting SonicWall Remote Access Boxes Before the Patch

A perfect-10 flaw in SonicWall's SMA1000 gateways was already under attack when the vendor shipped its July 14 hotfix. Here is what the filing actually says.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: a rack-mounted network security appliance in a dim server room, status LEDs glowing amber and red
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Rapid7's Managed Detection and Response team spotted hackers exploiting two SonicWall SMA1000 flaws as zero-days, meaning the vendor had no fix ready, before SonicWall's July 14, 2026 advisory went out.
  • The headline bug, CVE-2026-15409, scores a maximum 10.0 on the industry severity scale and needs no password to abuse.
  • A second bug, CVE-2026-15410, lets an attacker already inside the box run commands as the top-level "root" user.
  • Both bugs have been added to the US cyber agency's Known Exploited Vulnerabilities catalog, which forces federal agencies to patch on a deadline.
  • SonicWall SMA1000 appliances sit at the edge of corporate networks to give remote staff access, which makes them a standing target for ransomware crews.

SonicWall shipped hotfixes on July 14, 2026 for two flaws in its SMA1000 Series remote access appliances, the hardware that lets staff log in to work systems from home. One of them is as bad as the scoring system goes.

The critical bug is CVE-2026-15409, a server-side request forgery issue rated 10.0 on the CVSS scale. An attacker with no account on the device can trick it into opening a tunnel to internal services meant to be reached only from the machine itself.

The second flaw, CVE-2026-15410, is a code injection problem. Chained with the first bug, it lets an attacker run any operating system command as root, the account that owns the whole appliance.

Were these really being exploited before the patch?

Yes. Rapid7's incident responders say they watched targeted zero-day exploitation of internet-facing SMA1000-series boxes before SonicWall went public.

That matters because SonicWall's own advisory says it has no evidence that any of its four fixed flaws is being exploited. The vendor's wording covers all four; the responder's writeup is narrower, specific to these two. Read the record, not the summary. We first covered these CVEs on 14 July 2026, and as we reported on 2 September, the perfect-10 flaw was already being paired with the second bug in real attacks.

Both CVEs have since been added to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, the list that triggers mandatory patch deadlines for federal civilian agencies under Binding Operational Directive 22-01.

What are the actual numbers?

Item Detail
Advisory date July 14, 2026
Vendor SonicWall
Affected product SMA1000 Series appliances
CVE-2026-15409 SSRF, CVSS 10.0, unauthenticated
CVE-2026-15410 Command injection as root
Status Actively exploited; added to CISA KEV

What should an ordinary customer do?

If your employer runs a SonicWall SMA1000 at the edge of its network, the IT team needs to apply the latest platform hotfix now, not at the next maintenance window. Rapid7's finding means the clock started before the advisory did.

Remote access gateways from SonicWall and Fortinet have been a preferred way into corporate networks for ransomware crews for two years. Threat Vectr's own tracking of criminal leak sites continues to show a steady stream of victims listed after intrusions that began at an unpatched edge device.

My read: the gap between "no evidence of exploitation" in the vendor note and "actively exploited zero-day" in the responder's writeup is the story. Buyers should be pressing SonicWall on how CVE-2026-15409 reached a 10.0 severity score without being caught in pre-release testing, and whether the fix covers the full attack chain Rapid7 observed or only the entry point.

The KEV listing gives federal agencies a hard deadline. Everyone else should treat it as one too.

© 2026 Threat Vectr