← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE KEV ✓ (2 z 2) · ransomware EPSS 0.85 (nejvyšší)

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share…

Číst originál na Volexity →

3 zprávy z 3 zdrojů · první 15. 7. 12:11 · poslední 18. 7. 00:10 CZ · EN/orig

SonicWall US SE AT

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-15409 10.0 3.1 · CISA-ADP KEV ✓ 0.85
CVE-2026-15410 7.2 3.1 · CISA-ADP KEV ✓ 0.12

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Jak se o tom psalo 3

  1. · Volexity US nadpis události

    Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

    In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share…

  2. · CERT-SE SE

    Kritiska sårbarheter i SonicWall SMA1000

    SonicWall har publicerat säkerhetsuppdateringar gällande två sårbarheter (CVE-2026-15409 och CVE-2026-15410) i SMA1000-serien. [1] CISA har lagt till dessa sårbarheter i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]

  3. · CERT.at AT

    Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

    15. Juli 2026 Beschreibung In den SonicWall SMA1000 Series Appliances existieren mehrere Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung, die Appliance dazu zu bringen, serverseitig Anfragen an eigentlich nicht erreichbare interne Endpunkte zu senden (Server-Side Request Forgery). Laut SonicWall PSIRT werden die in diesem Advisory beschriebenen Schwachstellen bereits aktiv ausgenutzt. CVE-Nummer(n): CVE…