소닉월의 SMA 1000 시리즈에서 두 개의 제로데이 취약점이 악용되고 있다는 경고가 발표되었다.
소닉월은 SMA 1000 시리즈 장비에서 두 개의 제로데이 취약점이 악용되고 있다고 경고했다. 특히, CVE-2026-15409는 원격에서 인증 없이 악용될 수 있는 서버 측 요청 위조(SSRF) 취약점으로, 이러한 취약점을 통해 임의의 명령 실행이 가능하다. 이러한 상황은 보안에 큰 위험을 초래하므로 즉각적인 조치가 요구된다.
SonicWall warns of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances.
SonicWall has issued a warning about the active exploitation of two zero-day vulnerabilities affecting its SMA 1000 series appliances. Notably, CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability that could allow unauthenticated remote attackers to execute arbitrary commands. This situation poses significant risks to security and requires immediate action.