← Back to CVE List
Vulnerability Intelligence Report
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

CVE-2026-15409

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:78.44%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-918 ↗CWE-918: Server-Side Request Forgery (SSRF)

Affected Products & Versions

Vendor Product Affected Versions
SonicWall SMA1000 12.4.3-03245 <= 12.4.3-03434 (affected), 12.5.0-02283 <= 12.5.0-02800 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
78.440%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonicWall, Inc. · Vendor · USA
Reserved2026-07-10T14:12:14
Published2026-07-14T19:39:34
Patch Date2026-07-14
Last Updated2026-08-04T03:56:14

LINK COPIED TO CLIPBOARD