SonicWall confirms attackers are chaining two new SMA 1000 zero-days into remote code execution and urges immediate hotfixes.
Attackers used CVE-2026-15409 and CVE-2026-15410 to compromise SonicWall SMA 1000 appliances via SSRF and code injection starting June 22.