CVE-2026-15409
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Description
CVE-2026-15409 is a maximum-severity server-side request forgery (SSRF) vulnerability in the Work Place interface of SonicWall SMA1000 appliances, rated CVSS 10.0 (Critical). A remote, unauthenticated attacker can cause the appliance to make requests to unintended locations, without any user interaction and with a scope change that extends the impact beyond the vulnerable component itself. Because SMA1000 secure access appliances typically sit at the network edge, a successful SSRF exploit against them can expose internal services and fully compromise confidentiality, integrity, and availability. CISA has added CVE-2026-15409 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild, so affected SonicWall SMA6210, SMA7210, and SMA8200v deployments require immediate remediation.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sonicwall | sma6210 firmware | 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800 |
| sonicwall | sma7210 firmware | 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800 |
| sonicwall | sma8200v | 12.4.3-03245; 12.4.3-03387; 12.4.3-03434; 12.5.0-02283; 12.5.0-02624; 12.5.0-02800 |
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409(US Government Resource)
Weakness Type
CWE-918: Server-Side Request Forgery (SSRF)
Server-side request forgery occurs when an application fetches a remote resource without validating the user-supplied URL, allowing attackers to coerce it into sending requests to unexpected destinations — even ones protected by firewalls, VPNs, or network access control lists. In the SMA1000 Work Place interface, this weakness lets a remote unauthenticated attacker make the SonicWall appliance itself issue requests to locations of the attacker's choosing, turning the security gateway into a pivot toward internal services.
Learn more: CWE-918 — Server-Side Request Forgery (SSRF)
Impact Analysis
With a CVSS 3.1 score of 10.0 (Critical), CVE-2026-15409 sits at the top of the severity scale: it is remotely exploitable without physical access, easy to exploit with no special conditions, requires no authentication, and needs no user action. The Changed scope means the attack can affect resources beyond the vulnerable Work Place component — precisely the danger of SSRF on an edge appliance, where the device's trusted network position can be abused to reach internal services that firewalls and access control lists would otherwise shield. All three impact categories are rated High: sensitive data reachable through the appliance is at risk of disclosure (confidentiality), attacker-driven requests can alter systems and data (integrity), and services can be disrupted (availability). Given that SMA1000 appliances are secure access gateways deployed at the network perimeter, and that CISA has confirmed active exploitation via its KEV listing, unpatched appliances represent an acute risk of network-wide compromise.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2026-15409 in the wild by adding it to the Known Exploited Vulnerabilities catalog, with a remediation due date of 2026-07-17 that has already passed; ransomware usage is currently unknown. No public exploit code or proof-of-concept is referenced in the available sources, which consist of the SonicWall PSIRT advisory SNWLID-2026-0008 and the CISA KEV entry. The EPSS score of about 1.3% (67th percentile) does not yet indicate mass exploitation, but the combination of confirmed in-the-wild attacks, an unauthenticated network attack path, and a CVSS 10.0 rating on an internet-facing secure access appliance means affected organizations need to act immediately rather than wait for exploitation to broaden.
Remediation
- Follow the CISA KEV required action: apply mitigations in accordance with SonicWall's instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's Forensics Triage Requirements; discontinue use of the product if mitigations are unavailable. The KEV remediation due date was 2026-07-17, so remediation is already overdue for organizations subject to the directive.
- Update affected appliances per SonicWall advisory SNWLID-2026-0008. Vulnerable firmware versions on SMA6210, SMA7210, and SMA8200v include 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800 — upgrade to a fixed release as directed by the vendor.
- As an interim mitigation, restrict access to the Work Place interface: limit exposure of the appliance's web interfaces to the internet where operationally possible and filter access at upstream network controls.
- Apply SSRF-specific egress hardening in line with CWE-918 mitigation practice: restrict the appliance's outbound connectivity so it can only reach destinations it legitimately needs, and block requests from the appliance to internal management networks and private IP ranges that the Work Place function has no reason to contact.
- Review appliance and network logs for anomalous outbound requests originating from the SMA appliance — particularly requests to internal hosts or unexpected external destinations — and perform forensic triage per CISA guidance on any appliance that ran a vulnerable firmware version while exposed.
Technical Details
CVE-2026-15409 is a server-side request forgery (CWE-918) in the Work Place interface of SonicWall SMA1000 appliances: the application fetches resources based on attacker-influenced input without adequately validating the target, so a remote unauthenticated attacker can cause the appliance to issue requests to unintended locations. SSRF of this kind allows requests to be sent to destinations that perimeter defenses would normally protect, because the requests originate from the trusted appliance itself. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) documents the exploitability: network attack vector, low complexity, no privileges, no user interaction — and, critically, a Changed scope, meaning the security impact crosses from the vulnerable Work Place component into other resources, with High impact on confidentiality, integrity, and availability. The affected firmware lines span both the 12.4.3 and 12.5.0 release trains across SMA6210, SMA7210, and SMA8200v platforms.
Frequently Asked Questions
Is CVE-2026-15409 being actively exploited?
Yes. CISA has added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and the remediation due date of 2026-07-17 has already passed. The EPSS score of roughly 1.3% suggests exploitation is not yet widespread, and ransomware usage is currently unknown.
What products are affected by CVE-2026-15409?
The vulnerability affects the Work Place interface of SonicWall SMA1000 series appliances, specifically SMA6210, SMA7210, and SMA8200v. Vulnerable firmware versions include 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
How do I fix CVE-2026-15409?
Upgrade affected SMA6210, SMA7210, and SMA8200v appliances to fixed firmware following SonicWall advisory SNWLID-2026-0008. Until upgraded, restrict access to the Work Place interface, limit the appliance's outbound connectivity, and review logs for anomalous requests originating from the appliance.
How severe is CVE-2026-15409?
CVE-2026-15409 is rated Critical with the maximum CVSS 3.1 score of 10.0. It is exploitable remotely without authentication or user interaction, its Changed scope extends the impact beyond the vulnerable component, and confidentiality, integrity, and availability are all rated High. Combined with confirmed active exploitation and an EPSS score in the 67th percentile, it demands immediate remediation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.