• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-15409: pre-auth ssrf in SonicWall SMA1000 Appliances

A remote, unauthenticated attacker can make SonicWall SMA1000 Appliances perform arbitrary HTTP requests to unintended targets, allowing server-side request forgery (SSRF). CVE-2026-15409 affects SMA1000 Appliance builds in 12.x ranges 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. Exploitation requires only network access to the affected appliance’s service and no valid account or user interaction.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.06795
CWE
CWE-918
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent — CISA added this flaw to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline and the vulnerability has known ransomware campaign use, so prioritize mitigation for internet-facing SMA1000 Appliances immediately.

What is CVE-2026-15409?

A remote, unauthenticated attacker can make SonicWall SMA1000 Appliances perform arbitrary HTTP requests to unintended targets, allowing server-side request forgery (SSRF). CVE-2026-15409 affects SMA1000 Appliance builds in 12.x ranges 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. Exploitation requires only network access to the affected appliance’s service and no valid account or user interaction. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of SonicWall SMA1000 Appliances are affected?

BRANCHAFFECTEDFIXED
12.x12.4.3-03245 – 12.4.3-03434
12.x12.5.0-02283 – 12.5.0-02800

Is CVE-2026-15409 being exploited?

CISA added CVE-2026-15409 to the Known Exploited Vulnerabilities catalog on 2026-07-14, with federal remediation requirements by 2026-07-17; public exploit code is also available.

How to fix CVE-2026-15409

  1. Isolate SMA1000 Appliances from untrusted networks and remove direct internet exposure where possible.
  2. Apply any vendor-recommended mitigations and configuration hardening from SonicWall immediately.
  3. Monitor appliance logs and network traffic for signs of SSRF attempts and unusual outbound requests.
  4. Apply patches from SonicWall when a fixed release becomes available and verify affected builds are updated.

Frequently asked questions

Is CVE-2026-15409 being actively exploited?

Yes. CISA added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog on 2026-07-14, noting known ransomware campaign use and setting a remediation deadline of 2026-07-17 for federal agencies.

Which SMA1000 Appliances versions are affected by CVE-2026-15409?

SMA1000 Appliance builds in 12.x are affected: 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800.

Is there a patch for CVE-2026-15409?

No fixed release is listed in the supplied data; SonicWall has not published a fixed version for the affected builds in the provided information.

Does CVE-2026-15409 require authentication?

No. The vulnerability is exploitable by a remote, unauthenticated attacker with network access to the SMA1000 Appliance.

References