Known vulnerability record

CVE-2026-15409

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

Stable IDcve:CVE-2026-15409Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Keep the signals separate

CVSS severitycriticalScore 10 · source CISA-ADP
EPSS probability74.2%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-07-14
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-07-14
CVE modified
2026-08-04
KEV date added
2026-07-14
Dataset fetched
2026-08-21T03:55:01.506Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.