DIRAS TAKE
Urgent — CISA added this flaw to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline and the vulnerability has known ransomware campaign use, so prioritize mitigation for internet-facing SMA1000 Appliances immediately.
What is CVE-2026-15409?
A remote, unauthenticated attacker can make SonicWall SMA1000 Appliances perform arbitrary HTTP requests to unintended targets, allowing server-side request forgery (SSRF). CVE-2026-15409 affects SMA1000 Appliance builds in 12.x ranges 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. Exploitation requires only network access to the affected appliance’s service and no valid account or user interaction. The weakness is classified as CWE-918 (Server-Side Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of SonicWall SMA1000 Appliances are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 12.x | 12.4.3-03245 – 12.4.3-03434 | |
| 12.x | 12.5.0-02283 – 12.5.0-02800 |
Is CVE-2026-15409 being exploited?
CISA added CVE-2026-15409 to the Known Exploited Vulnerabilities catalog on 2026-07-14, with federal remediation requirements by 2026-07-17; public exploit code is also available.
How to fix CVE-2026-15409
- Isolate SMA1000 Appliances from untrusted networks and remove direct internet exposure where possible.
- Apply any vendor-recommended mitigations and configuration hardening from SonicWall immediately.
- Monitor appliance logs and network traffic for signs of SSRF attempts and unusual outbound requests.
- Apply patches from SonicWall when a fixed release becomes available and verify affected builds are updated.
Frequently asked questions
Is CVE-2026-15409 being actively exploited?
Yes. CISA added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog on 2026-07-14, noting known ransomware campaign use and setting a remediation deadline of 2026-07-17 for federal agencies.
Which SMA1000 Appliances versions are affected by CVE-2026-15409?
SMA1000 Appliance builds in 12.x are affected: 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800.
Is there a patch for CVE-2026-15409?
No fixed release is listed in the supplied data; SonicWall has not published a fixed version for the affected builds in the provided information.
Does CVE-2026-15409 require authentication?
No. The vulnerability is exploitable by a remote, unauthenticated attacker with network access to the SMA1000 Appliance.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15409
- cve.org/CVERecord?id=CVE-2026-15409
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- All SonicWall CVEs on CVE Radar
- CVEs published in September 2026