Vulnerability intelligence
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVSS Score
10
Critical
EPSS — Exploit Probability
84%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-17
14 articles across 8 outlets · first covered Jul 14, 2026 · latest Aug 4, 2026
Associated threat actors
Coverage timeline
-
INC Ransomware abuses CVE-2026-15409 in SonicWall, calls victimssecurityaffairs.com · Aug 4, 2026
-
INC Ransomware exploits CVE-2026-15409, gains root on SonicWallwww.securityweek.com · Aug 3, 2026
-
SonicWall SMA Exploit Chain Now Fuels INC Ransomware Attackssecurityonline.info · Aug 3, 2026
-
SonicWall SMA 1000 zero day used to spread KNUCKLEBALLsocradar.io · Jul 21, 2026
-
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patchwww.securityweek.com · Jul 20, 2026
-
Zero day exploits hit SonicWall VPN, giving attackers root accesssecurityaffairs.com · Jul 20, 2026
-
Zero day exploit targets SonicWall SMA 1000, installs malwaresecurityonline.info · Jul 19, 2026
-
SonicWall CVE-2026-15409 flaw lets ransomware group hijack VPNswww.darkreading.com · Jul 17, 2026
-
Microsoft, SonicWall bugs found; RabbitMQ patches auth flawssecurityonline.info · Jul 15, 2026
-
SonicWall SMA1000 flaws exploited, urgent patch advisedwww.rapid7.com · Jul 15, 2026
-
CISA Flags SonicWall SMA1000 and Microsoft Flaws in KEV Catalogsecurityaffairs.com · Jul 15, 2026
-
SonicWall Warns of Active Exploitation of SMA 1000 Zero Dayssecurityaffairs.com · Jul 15, 2026
-
CISA KEV Catalog Highlights SonicWall SMA1000 Flaw CVE-2026-15409www.cisa.gov · Jul 14, 2026
-
CISA Lists SonicWall SMA1000 SSRF Flaw in KEV, Urges Patchcisa.gov · Jul 14, 2026