The vulnerabilities affect the SMA 6210, 7210, and 8200v models, with hotfixes now available from SonicWall. The vendor recommended that customers contact its technical support team for help identifying indicators of compromise. If an appliance appears compromised, SonicWall advises reimaging or redeploying it, changing all passwords, and resetting TOTP tokens.
The disclosure marks the latest in a difficult run for SonicWall's SMA1000 line stretching back through 2025. In July, the vendor disclosed a nearly identical pair of vulnerabilities – another pre-authentication SSRF and a post-authentication OS command injection – the former also receiving a CVSS 10.0 rating. That earlier SSRF bug (CVE-2026-15409) was later added to CISA's Known Exploited Vulnerabilities catalog and was known to have been used in ransomware campaigns.
NHS England issued its own advisory, warning about the growing risk of attacks against internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," the health service's National Cyber Security Operations Centre stated, assessing future exploitation as "almost certain."