HispasecJuly 18, 2026🇪🇸Translated from Spanish

SonicWall Issues Emergency Hotfixes After Detecting Active Exploitation of Two Zero-Day Vulnerabilities in SMA1000 Appliances

SonicWall has confirmed the active exploitation of two zero-day vulnerabilities in its SMA1000 series appliances, triggering an emergency response and the rapid release of hotfixes. The company detected real-world intrusions targeting these perimeter devices, which provide remote access to corporate networks, significantly elevating risk for any organization with internet-exposed units.

The first vulnerability, CVE-2026-15409, received a maximum CVSS 10.0 score and involves unauthenticated server-side request forgery (SSRF) in the SMA1000 Appliance Work Place interface. This flaw allows remote attackers to compel the appliance to send requests to unintended internal destinations, serving as a common foothold for pivoting deeper into corporate environments.

The second issue, CVE-2026-15410, carries a CVSS 7.2 rating and affects the SMA1000 Appliance Management Console. It enables authenticated code injection, permitting an administrator to execute operating system commands. In sophisticated attacks, this type of vulnerability is frequently used to establish persistence, alter configurations, or maintain long-term access.

Affected Products and Available Fixes

Impacted models include SMA6210, SMA7210, and SMA8200v. Vulnerable platform versions encompass 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall has released corrected hotfixes 12.4.3-03453 and 12.5.0-02835, along with subsequent updates. No alternative mitigations are considered sufficient; organizations must apply these patches.

Exploitation and Regulatory Response

Attacks observed in the wild may chain both vulnerabilities, although confirmation varies across sources. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog, mandating that U.S. federal agencies apply fixes or decommission affected systems by July 17, 2026. The vulnerabilities do not impact SonicWall SSL VPN firewalls or the SMA 100 Series appliances.

Indicators of Compromise and Recommended Actions

Key indicators of compromise include HTTP 200 responses for /api/login or /api/logout requests in extraweb_access.log, suspicious /wsproxy calls returning HTTP 101, evidence of unauthorized hotfix rollbacks in ctrl-service.log, and anomalous paths in /var/lib/unit/conf.json.

  • Immediately update exposed SMA1000 appliances to versions 12.4.3-03453 or 12.5.0-02835.
  • Inventory all SMA6210, SMA7210, and SMA8200v devices and prioritize those with administrative exposure.
  • Review logs for listed IOCs and preserve evidence for forensic analysis if compromise is suspected.
  • Reimage physical appliances or redeploy virtual instances before returning them to production.
  • Rotate all user and administrator passwords, reset TOTP tokens, and restrict administrative access to management networks or bastions.
  • Implement monitoring for anomalous /wsproxy host parameters and /api/login or /api/logout activity.

Additional details are available from BleepingComputer, Help Net Security, and The Hacker News.

Related articles

HabrVulnerabilities & Exploits

RCE Vulnerability in AI Code Editors Cursor, VS Code and Google Antigravity Threatens 50 Million Developers

Researchers at AISLE discovered a critical remote code execution vulnerability affecting the AI-powered code editors Cursor, Microsoft Visual Studio Code and Google Antigravity. The flaw allowed attackers to achieve RCE simply by tricking a developer into opening a specially crafted link embedded in a Git commit message. Successful exploitation granted full access to API keys, local files, and the ability to install persistent malware without any visible indicators. The issue stemmed from shared architectural components inherited from the Visual Studio Code codebase, which Cursor and Google Antigravity both adopted. All three vendors have released patches, yet the incident highlights systemic supply-chain risks in the rapidly growing AI-IDE ecosystem. Approximately 50 million developers were potentially exposed before fixes were deployed.

HabrVulnerabilities & Exploits

NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU

Neoflex has released NEOMSA APIM 4.6.0 with a primary focus on strengthening the security of the platform's supply chain. The team generated an SBOM in CycloneDX format, scanned components and dependencies using Grype, and cross-referenced findings against the FSTEC BDU database. This process reduced total registered vulnerabilities from 57 to 7, completely removing all 10 Critical and 24 High issues. The platform now meets the formal Security Gate criterion requiring zero Critical or High vulnerabilities from the FSTEC database in the final build. Remaining Medium findings are documented and tracked for future updates. The release provides customers with a verified, transparent component inventory that simplifies compliance and integration reviews.

Security NEXTVulnerabilities & Exploits

Cisco Publishes 12 Security Advisories Fixing Critical Flaws in Catalyst SD-WAN and IOS XE

Cisco Systems released 12 new security advisories on August 5, 2026, disclosing a total of 23 vulnerabilities across multiple products. Two advisories covering Cisco Catalyst SD-WAN Software and Cisco IOS XE Software received the highest Critical severity rating. The SD-WAN advisory addresses five issues, including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring 9.9 on CVSSv3.1. The IOS XE advisory details seven vulnerabilities, with CVE-2026-20272 rated 9.8 and CVE-2026-20267 rated 9.0. Additional advisories cover flaws in Integrated Management Controller, RoomOS, and Terminal Services Agent. Organizations are urged to apply the hardening releases immediately to mitigate remote exploitation risks.

AntiMalwareVulnerabilities & Exploits

Head Mare Hackers Exploit TrueConf Servers to Distribute PhantomCore and PhantomGraph Backdoors

Russian organizations have been targeted in a new campaign by the Head Mare group, which compromises unpatched TrueConf servers to deliver backdoors. Attackers chain vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with maximum privileges on affected servers. They then replace a server file with a web shell to explore the victim's infrastructure, access the TrueConf database, and substitute the client installer. Victims are tricked via social engineering into downloading the malicious client during video conferences without any suspicious emails. The campaign affects TrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. Kaspersky researchers recommend immediate updates to patched versions 5.3.9, 5.4.9, and 5.5.5 released on 18 June 2026. The threat extends beyond direct TrueConf users, as any employee invited to a compromised server can inadvertently install the backdoor.