Vulnerability record · CVE-2026-15409 · published 14 July 2026
CVE-2026-15409: SonicWall SMA1000 Work Place SSRF allows unauthenticated requests
Sonicwall · Sma6210 Firmware
The SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests to unintended locations. It is remotely reachable without authentication and carries a maximum CVSS 3.1 score of 10.0, so it warrants immediate attention for any internet-exposed appliance.
Description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityMaximum CVSS score of 10.0, unauthenticated network reachability, KEV listing with known ransomware use, and a 99.7th percentile EPSS probability make this an urgent patch-or-isolate case.
What it is
The SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests to unintended locations. It is remotely reachable without authentication and carries a maximum CVSS 3.1 score of 10.0, so it warrants immediate attention for any internet-exposed appliance.
Impact
An attacker can force the appliance to issue requests to arbitrary destinations, which can be used to reach internal services or metadata endpoints that are otherwise unreachable from outside. The CVSS vector rates confidentiality, integrity and availability impact as high with scope change, so full compromise of the appliance and its reachable network is plausible.
Attack surface
Reached over the network through the Work Place interface of the SMA1000 appliance; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required. Only appliances with that interface exposed are in scope.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2026-07-14 with a remediation due date of 2026-07-17 and flags known ransomware campaign use, and EPSS gives a 30-day exploitation probability of 0.845 (99.7th percentile), so active exploitation should be assumed.
What to do
- Apply the SonicWall vendor fix per advisory SNWLID-2026-0008 immediately, following CISA BOD 26-04 guidance.
- If no patch is available, restrict or disable external access to the SMA1000 Work Place interface and discontinue use where mitigations cannot be applied.
- Isolate affected SMA1000 appliances (SMA6210, SMA7210, SMA8200v) on a segmented network so SSRF cannot reach internal services or cloud metadata endpoints.
- Block outbound traffic from the appliance to internal address ranges and link-local metadata addresses unless explicitly required.
- Treat any appliance that was internet-exposed as potentially compromised and perform the CISA forensics triage steps.
Detection
- Review appliance and perimeter logs for requests to the Work Place interface from unexpected external sources, especially around the KEV addition date.
- Monitor outbound connections from SMA1000 appliances to internal hosts, loopback, or cloud metadata addresses (for example 169.254.169.254) for signs of SSRF.
- Hunt for post-exploitation activity consistent with ransomware staging on hosts reachable from the appliance.
- Check for unauthorized configuration changes or new accounts on the appliance following suspected exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-15409 to the Known Exploited Vulnerabilities catalog on 14 July 2026 as "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 17 July 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409 | US Government Resource |
Track CVE-2026-15409 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-15409), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.