Overview
SonicWall has released a security advisory addressing two zero-day vulnerabilities in the SMA1000 Appliance Work Place Interface and SMA1000 Appliance Management Console (AMC). SonicWall reported that there have been investigations for multiple cases that have indicated active exploitation of both vulnerabilities. Successful exploitation could allow an attacker to force a vulnerable appliance to make unauthorised internal requests, bypass security controls, and potentially execute arbitrary operating system commands on the device.
- CVE-2026-15409: Server-Side Request Forgery (SSRF) Vulnerability (CVSSv3 10.0)
- CVE-2026-15410: Code Injection Vulnerability (CVSSv3 7.2)
Affected Versions:
- SMA100 Models – 6210, 7210, 8200v
- 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)
- 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
Zoom has released a security advisory addressing a critical vulnerability in Zoom Workplace for Windows and Zoom VDI Client for Windows. This vulnerability could allow an unauthenticated, remote attacker to manipulate how the application processes input data, potentially enabling account takeover. Successful exploitation could lead to unauthorised access to Zoom accounts, modification of account settings, and access to sensitive meeting information.
- CVE-2026-53412: Improper Input Validation Vulnerability (CVSSv3 9.8)
Affected Versions:
- Zoom Workplace for Windows < 7.0.0
- Zoom Workplace VDI Client for Windows < 7.0.10, < 6.6.15, < 6.5.18
Mozilla has released a security advisory addressing two vulnerabilities in Firefox where exploit code is publicly available, although no attacks have been observed in the wild. These vulnerabilities could allow an attacker to use specially crafted web contents to corrupt browser memory, bypass site isolation protection, or access data that should be restricted to other website or browser contexts. Successful exploitation could lead to sensitive information disclosure, session compromise, arbitrary code execution within the browser, and further compromise of the affected user’s system.
- CVE-2026-15718: Invalid Pointer Vulnerability (CVSSv3 4.3)
- CVE-2026-15719: Site Isolation Vulnerability (CVSSv3 5.4)
Affected Versions: Firefox < 152.0.6
Google Chrome has released a security advisory addressing multiple vulnerabilities, including two use-after-free flaws in Chrome’s Ozone and Views components. These vulnerabilities occur when the browser continues to access memory after it has been released, which can lead to memory corruption. Successful exploitation could allow a remote attacker to execute arbitrary code by convincing a user to visit a specially crafted HTML page, potentially resulting in sensitive information disclosure, security control bypass, or compromise of the affected system.
- CVE-2026-15112: Use-After-Free Vulnerability (CVSSv3 8.8)
- CVE-2026-15129: Use-After-Free Vulnerability (CVSSv3 8.8)
Affected Versions: Google Chrome < 150.0.7871.115
Recommended Action
Organisations are encouraged to review the appropriate security advisory pages and apply the updates:
SonicWall – Security Advisory | SonicWall
Zoom – Security Advisory | Zoom
Mozilla – Security Advisory | Mozilla
Chrome – Security Advisory | Chrome
If you have any concerns, or have been affected by a cyber-related issue, report it to us by submitting a Cyber Concerns Online Reporting Form.