CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVE-2026-15409CVSS 10.0CISA KEVKnown Exploited

CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS
10.0 CRITICAL
EPSS
96.62%
Known exploited
yes
Product
SMA1000 Appliances

What is known

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Sources

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer