THREAT OPS › CVEs › CVE-2026-15409
CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Vulnerability details
- Affected productsSMA1000 Appliances
- KEV remediation due2026-07-17
Related reporting
- Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimetertenable
- Metasploit Wrap Up: Lot of summer shells and fit http profilesrapid7
- July 2026 CVE Landscaperecordedfuture
- [CISA KEV] CVE-2026-15409 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa_kev
- 20th July – Threat Intelligence Reportcheckpoint_research
- Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitationvolexity
- CVE-2026-15409 / CVE-2026-15410 | SonicWall SMA1000 Server-Side Request Forgery and Code Injection Vulnerabilitieshorizon3
- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildtenable
- Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)rapid7