CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Other sources
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15409?
The severity of CVE-2026-15409 is critical with a CVSS score of 10.
How do I fix CVE-2026-15409?
To fix CVE-2026-15409, apply the latest security patches provided by SonicWall for the SMA1000 Appliances.
What type of vulnerability is CVE-2026-15409?
CVE-2026-15409 is a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2026-15409?
Organizations using SonicWall SMA1000 Appliances with the Work Place interface are affected by CVE-2026-15409.
Can CVE-2026-15409 be exploited remotely?
Yes, CVE-2026-15409 can be exploited by a remote unauthenticated attacker.