All CVEs
Vulnerability intelligence

CVE-2026-15409

CWE-918

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS Score
10
Critical
EPSS — Exploit Probability
84%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-17
NVD entry Vendor patch PoC / advisory CISA KEV

14 articles across 8 outlets · first covered Jul 14, 2026 · latest Aug 4, 2026

Associated threat actors

Coverage timeline