CVE-2026-15409
Last modified
CVE-2026-15409 is a critical-severity vulnerability rated 10/10 on the CVSS scale. A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.. CISA has confirmed active exploitation in the wild. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Sma6210 Firmware | 12.4.3-03245 |
| Sonicwall | Sma6210 Firmware | 12.4.3-03387 |
| Sonicwall | Sma6210 Firmware | 12.4.3-03434 |
| Sonicwall | Sma6210 Firmware | 12.5.0-02283 |
| Sonicwall | Sma6210 Firmware | 12.5.0-02624 |
| Sonicwall | Sma6210 Firmware | 12.5.0-02800 |
| Sonicwall | Sma7210 Firmware | 12.4.3-03245 |
| Sonicwall | Sma7210 Firmware | 12.4.3-03387 |
| Sonicwall | Sma7210 Firmware | 12.4.3-03434 |
| Sonicwall | Sma7210 Firmware | 12.5.0-02283 |
| Sonicwall | Sma7210 Firmware | 12.5.0-02624 |
| Sonicwall | Sma7210 Firmware | 12.5.0-02800 |
| Sonicwall | Sma8200v | 12.4.3-03245 |
| Sonicwall | Sma8200v | 12.4.3-03387 |
| Sonicwall | Sma8200v | 12.4.3-03434 |
| Sonicwall | Sma8200v | 12.5.0-02283 |
| Sonicwall | Sma8200v | 12.5.0-02624 |
| Sonicwall | Sma8200v | 12.5.0-02800 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-15409?
How severe is CVE-2026-15409?
How do I fix CVE-2026-15409?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15401The VikBooking Hotel Booking Engine & PMS plugin for WordPre…7.2
- CVE-2026-15402The Eventin – Event Calendar, Event Registration, Tickets & …6.4
- CVE-2026-15403The Pinpoint Booking System – Version 2 plugin for WordPress…4.9
- CVE-2026-15404The Lpagery plugin for WordPress is vulnerable to Stored Cro…6.4
- CVE-2026-15406The Eventin – Event Calendar, Event Registration, Tickets & …7.5
- CVE-2026-15407The Themify Builder plugin for WordPress is vulnerable to au…4.3
- CVE-2026-1541The Avada (Fusion) Builder plugin for WordPress is vulnerabl…4.3
- CVE-2026-15410Post-authentication improper control of generation of code (…7.2
- CVE-2026-15411The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO,…5.3
- CVE-2026-15412IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSph…6.5
- CVE-2026-15413The Link Factory WordPress plugin is a backdoor. Distributed…10
- CVE-2026-15414The Subscriptions for WooCommerce plugin for WordPress is vu…8.8
Are you affected by CVE-2026-15409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
