Hispasec•July 18, 2026•🇪🇸Translated from Spanish

SonicWall Issues Emergency Hotfixes After Detecting Active Exploitation of Two Zero-Day Vulnerabilities in SMA1000 Appliances

SonicWall has confirmed the active exploitation of two zero-day vulnerabilities in its SMA1000 series appliances, triggering an emergency response and the rapid release of hotfixes. The company detected real-world intrusions targeting these perimeter devices, which provide remote access to corporate networks, significantly elevating risk for any organization with internet-exposed units.

The first vulnerability, CVE-2026-15409, received a maximum CVSS 10.0 score and involves unauthenticated server-side request forgery (SSRF) in the SMA1000 Appliance Work Place interface. This flaw allows remote attackers to compel the appliance to send requests to unintended internal destinations, serving as a common foothold for pivoting deeper into corporate environments.

The second issue, CVE-2026-15410, carries a CVSS 7.2 rating and affects the SMA1000 Appliance Management Console. It enables authenticated code injection, permitting an administrator to execute operating system commands. In sophisticated attacks, this type of vulnerability is frequently used to establish persistence, alter configurations, or maintain long-term access.

Affected Products and Available Fixes

Impacted models include SMA6210, SMA7210, and SMA8200v. Vulnerable platform versions encompass 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall has released corrected hotfixes 12.4.3-03453 and 12.5.0-02835, along with subsequent updates. No alternative mitigations are considered sufficient; organizations must apply these patches.

Exploitation and Regulatory Response

Attacks observed in the wild may chain both vulnerabilities, although confirmation varies across sources. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog, mandating that U.S. federal agencies apply fixes or decommission affected systems by July 17, 2026. The vulnerabilities do not impact SonicWall SSL VPN firewalls or the SMA 100 Series appliances.

Indicators of Compromise and Recommended Actions

Key indicators of compromise include HTTP 200 responses for /api/login or /api/logout requests in extraweb_access.log, suspicious /wsproxy calls returning HTTP 101, evidence of unauthorized hotfix rollbacks in ctrl-service.log, and anomalous paths in /var/lib/unit/conf.json.

  • Immediately update exposed SMA1000 appliances to versions 12.4.3-03453 or 12.5.0-02835.
  • Inventory all SMA6210, SMA7210, and SMA8200v devices and prioritize those with administrative exposure.
  • Review logs for listed IOCs and preserve evidence for forensic analysis if compromise is suspected.
  • Reimage physical appliances or redeploy virtual instances before returning them to production.
  • Rotate all user and administrator passwords, reset TOTP tokens, and restrict administrative access to management networks or bastions.
  • Implement monitoring for anomalous /wsproxy host parameters and /api/login or /api/logout activity.

Additional details are available from BleepingComputer, Help Net Security, and The Hacker News.

Related articles

Hispasec•Vulnerabilities & Exploits

Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release

Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.

AntiMalware•Vulnerabilities & Exploits

LibreOffice and Apache OpenOffice Flaw Enables Remote Code Execution via Malicious Calc Tables Without Macro Warnings

Researchers have demonstrated an attack against LibreOffice and Apache OpenOffice users that executes arbitrary Java code simply by opening a malicious spreadsheet, without requiring macro permissions or triggering any security prompts. The vulnerability requires Java support to be enabled in the office suite and exploits legitimate features in the Calc component that automatically fetch data from external database sources. When a crafted document is opened, Calc loads a linked database file that references a malicious Java driver, allowing the attacker’s code to run inside the office process. LibreOffice has already patched the issue tracked as CVE-2026-63277 with the release of versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains vulnerable up to version 4.1.16 under CVE-2026-59265 with a fix expected in 4.1.17. The attack chain works on both Windows and Linux and bypasses macro protections entirely because no user consent dialog appears. Although only a proof-of-concept exploit that launches the calculator has been published so far, the same technique can execute any Java payload. Users of OpenOffice are advised to disable Java or avoid untrusted files until the patch is available.

BoletimSec•Vulnerabilities & Exploits

Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence

Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.

BoletimSec•Vulnerabilities & Exploits

Apache Struts CVE-2026-104711 Enables Remote Code Execution via Legacy RESTful Mapper

Apache Struts has patched four vulnerabilities, one of which permits unauthenticated remote code execution through an OGNL injection flaw. The issue, tracked as CVE-2026-104711, only affects applications that still rely on the legacy RESTful mapper; modern configurations using the default mapper, restful2, or the official Struts REST plugin remain unaffected. Exploitation occurs when the legacy mapper extracts action names and parameters directly from the URL, allowing attackers to inject malicious OGNL expressions. Vulnerable releases span 2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, and 7.0.0–7.3.0, with fixes available in 6.12.0 and 7.4.0. The remaining three flaws impact availability or cause cross-request data leakage but do not lead to code execution, and only one received an “important” severity rating.