Story perspectives
SonicWall Issues Critical Hotfixes; Agencies Must Patch by July 17
7/15/2026
1 of 1
Story summary
- SonicWall warned that actively exploited CVE-2026-15409 (critical SSRF, CVSS 10.0) and CVE-2026-15410 (high-severity code injection, CVSS 7.2) require hotfixes 12.4.3-03453 and 12.5.0-02835.
- CISA placed the flaws in its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch them by July 17 2026.
- SonicWall advised customers to review logs after updating and provided a remediation script for affected appliances.
