CVE
CVE-2026-15409
- First Reported
- Jul 17, 2026
- Latest Reported
- Oct 7, 2026
Reported Context (4)
- In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S. SonicWall patches maximum-severity SSRF flaw in SMA1000 gateways
- with moderate confidence that the incident is linked to an actor performing mass exploitation of CVE-2026-15409 against SonicWall SMA1000 appliances. The operator gained command execution on appliances, extracted Hunt.io Links UK Council Attack to SonicWall SMA1000 Exploitation Campaign
- initial access through a SonicWall SMA appliance, by exploiting the vulnerability chain disclosed as CVE-2026-15409 and CVE-2026-15410. Sophos Finds Fake AI Installers Dominated Malware Cases
- CVE-2026-15409 (SSRF) Volexity Details Zero-Day Exploitation of SonicWall SMA VPN Appliances
CVE (5)
Malware (7)
People (2)
Threat Actors (6)
MITRE ATT&CK (31)
Vendors (7)
Products (17)
Tools (24)
Industries (10)
Countries (12)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.