LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 14, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 17, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog on Jul 14, 2026, with a federal patch deadline of Jul 17, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended…

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that permits a remote unauthenticated attacker to cause the appliance to issue requests to locations chosen by the attacker. The issue matters because these appliances commonly sit at the edge of networks and handle remote access traffic; successful abuse can expose internal resources or services that the appliance can reach.

How it works

The weakness is categorized as CWE-918, server-side request forgery. In this class of flaw an attacker supplies a crafted URL or resource identifier to the affected application. The application then performs an outbound request to that identifier without sufficient validation of the destination. Because the request originates from the appliance itself, it may reach internal systems, metadata services, or other locations that would otherwise be unreachable from the attacker’s position.

Am I affected? How to find it in your systems

Inventory all deployed SonicWall SMA1000 Appliances and confirm whether they are reachable from the internet or from untrusted networks. Check the firmware and configuration versions running on each unit against the details listed in the vendor advisory. Review network diagrams and firewall rules to identify any appliances that accept unauthenticated or lightly authenticated connections. Examine logs for unexpected outbound requests originating from the appliances to internal IP ranges or unusual hostnames.

How to remediate

Apply the vendor-supplied update or configuration change referenced in the official advisory. After patching, review the appliance’s outbound request handling settings and restrict destinations to only those explicitly required for operation. Confirm that any proxy or URL-handling features follow the principle of least privilege for external resource access.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to further compromise and data exposure. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether related credentials or information have already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SMA1000 Appliances
WeaknessCWE-918
Added to CISA KEVJul 14, 2026
Federal patch deadlineJul 17, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities