CVE-2026-15409
Description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
In plain language
AI Act nowCVE-2026-15409 is a critical flaw in the sma1000 appliance that lets an attacker make the device send network requests to unintended places—without logging in—and it is already being exploited in the wild, so small businesses should act immediately if they use this appliance.
Unauthenticated SSRF in the SMA1000 Appliance Work Place interface allows remote attackers to induce the device to make HTTP requests to arbitrary locations (no authentication or user interaction required), enabling internal network targeting and potential data theft; the issue is confirmed in CISA KEV and being exploited in the wild.
What to do now
- Identify whether you use the sma1000 appliance and confirm it has the SMA1000 Appliance Work Place interface enabled.
- Check with your SonicWall/SMA vendor portal, support ticket, or release notes for any mitigation or fixed firmware/package for CVE-2026-15409, since patch details are not included here.
- If no fix is available yet, follow SonicWall’s vendor instructions for mitigations for CVE-2026-15409 and reduce exposure per CISA guidance.
- Contact your IT/security contact to begin forensic review for signs of compromise related to unexpected outbound requests from the appliance immediately.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEen·Dark Reading· Exploited SonicWall SMA 1000 zero-day
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chainen·The Hacker News· Exploited SonicWall SMA 1000 Series zero-day
- SonicWall SMA 1000 appliances under attack via zero-day flawsen-us·Help Net Security· Exploited SonicWall SMA 1000 Appliances zero-day
- SonicWall warns of actively exploited SMA1000 zero-day flawsen-us·BleepingComputer· Exploited SMA1000 zero-day
- Metasploit Wrap Up: Lot of summer shells and fit http profilesen·Rapid7 Blog· PoC Metasploit rce
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangsen-us·BleepingComputer· Exploited SMA1000 Qilin
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flawsen·The Hacker News· Exploited SonicWall SMA 1000 INC Ransomware
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacksen-us·SecurityWeek· Exploited SMA1000 INC Ransomware
- Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breacheden-us·Help Net Security· Roundup ServiceNow AI Platform
- New InfraTrust report reveals infrastructure flaws admins should patch firsten-us·BleepingComputer· Exploited SMA1000 Volt Typhoon
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-15409 and every CVE in our database. Create a free account — no credit card required.
Create Free Account