Trust & Security
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first — this is the origin story.
◆ Heath Callahan