SonicWall security patch release for CVE-2026-15409
Security Patch Release
Summary
Hide ▲
Show ▼
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are available in platform-hotfix 12.4.3-03453 and 12.5.0-02835 or later, covering affected SMA1000 models 6210, 7210, and 8200v. Customers were told to upgrade as soon as possible and check for compromise indicators. CISA KEV listing and the vendor's guidance indicate urgent remediation for exposed deployments.
Related Happenings
Alibaba Fastjson SafeMode mitigation for CVE-2026-16723
Advisory/Mitigation
H score44
First: 25.07.2026 15:52
Last: 25.07.2026 15:52
Sources 1
About this happening:
Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code...
Alibaba Fastjson SafeMode mitigation for CVE-2026-16723
Advisory/MitigationAbout this happening: Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score56
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
How related:
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionHow related: The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch Release
H score45
First: 22.05.2026 11:19
Last: 22.05.2026 11:19
Sources 1
About this happening:
TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch ReleaseAbout this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch Release
H score55
First: 22.05.2026 08:36
Last: 22.05.2026 08:36
Sources 1
About this happening:
Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch ReleaseAbout this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Timeline
-
15.07.2026 00:23 3 articles · 13d ago
SonicWall warns of active exploitation in SMA1000 and releases hotfixes
Initial DisclosureSonicWall warned that threat actors were actively exploiting CVE-2026-15409 and CVE-2026-15410 in zero-day attacks against SMA1000 models 6210, 7210, and 8200v, released hotfix versions 12.4.3-03453 and 12.5.0-02835 or later, published indicators of compromise for extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json, and urged administrators to upgrade, re-image compromised appliances, and reset user credentials and TOTP tokens. CISA also added both vulnerabilities to the KEV catalog, and federal agencies were told to secure affected systems by July 17, 2026, or discontinue use of the product if mitigations could not be applied.
Show sources
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now — www.bleepingcomputer.com — 15.07.2026 00:23
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now — www.bleepingcomputer.com — 15.07.2026 00:23
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — thehackernews.com — 15.07.2026 08:30