CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability. SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
- CISA KEV-listed (remediation due 2026-07-17)
- used in ransomware campaigns
- EPSS 83.7% (99.7% percentile)
- CVSS 10 critical
Related briefings
- Patching is not enough for exploited SonicWall bugs 2026-09-02
- Spies and ransomware crews exploit the same edge devices 2026-08-26
- Most AI attacks are still fake installers, Sophos finds 2026-08-19
- Akira reboots PCs into Safe Mode to blind security tools 2026-08-19
- Metasploit ships working exploits for flaws under attack 2026-08-15