CVE-2026-15409 is a critical SSRF vulnerability (CVSS 10.0) in SonicWall SMA1000 appliances actively exploited in the wild. Patch immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| sma6210_firmware | 12.4.3-03245 | 12.4.3-03245 | vulnerable |
| sma6210_firmware | 12.4.3-03387 | 12.4.3-03387 | vulnerable |
| sma6210_firmware | 12.4.3-03434 | 12.4.3-03434 | vulnerable |
| sma6210_firmware | 12.5.0-02283 | 12.5.0-02283 | vulnerable |
| sma6210_firmware | 12.5.0-02624 | 12.5.0-02624 | vulnerable |
| sma6210_firmware | 12.5.0-02800 | 12.5.0-02800 | vulnerable |
| sma6210 | - | - | unaffected |
| sma7210_firmware | 12.4.3-03245 | 12.4.3-03245 | vulnerable |
| sma7210_firmware | 12.4.3-03387 | 12.4.3-03387 | vulnerable |
| sma7210_firmware | 12.4.3-03434 | 12.4.3-03434 | vulnerable |
| sma7210_firmware | 12.5.0-02283 | 12.5.0-02283 | vulnerable |
| sma7210_firmware | 12.5.0-02624 | 12.5.0-02624 | vulnerable |
| sma7210_firmware | 12.5.0-02800 | 12.5.0-02800 | vulnerable |
| sma7210 | - | - | unaffected |
| sma8200v | 12.4.3-03245 | 12.4.3-03245 | vulnerable |
| sma8200v | 12.4.3-03387 | 12.4.3-03387 | vulnerable |
| sma8200v | 12.4.3-03434 | 12.4.3-03434 | vulnerable |
| sma8200v | 12.5.0-02283 | 12.5.0-02283 | vulnerable |
| sma8200v | 12.5.0-02624 | 12.5.0-02624 | vulnerable |
| sma8200v | 12.5.0-02800 | 12.5.0-02800 | vulnerable |
| sma8200v | - | - | unaffected |
SonicWall has released urgent firmware updates to address this SSRF vulnerability. Administrators should immediately visit the SonicWall support portal to download and install the latest security patches for the SMA 1000 series.
Ensure all SMA 6210, 7210, and 8200v appliances are upgraded from vulnerable firmware versions, specifically those in the 12.4.3-03xxx and 12.5.0-02xxx series, to the recommended fixed versions provided by the vendor.
Limit access to the SMA Work Place interface to trusted IP addresses only. Implement strict egress filtering on the appliance to prevent it from initiating unauthorized connections to internal resources or suspicious external domains.
Conduct a forensic triage as per CISA BOD 26-04 guidelines. Review appliance logs for unusual outbound traffic patterns, specifically requests originating from the Work Place interface directed toward internal metadata services or private IP ranges.
"Detection should focus on identifying abnormal outbound HTTP/HTTPS requests originating from the SMA1000 appliance. Monitor web server logs for requests to the 'Work Place' interface containing suspicious URL parameters or IP addresses in the payload. Look for indicators of lateral movement, such as the appliance attempting to communicate with internal management interfaces (e.g., 169.254.169.254 or internal database ports) that it typically does not access."
Experience superior visibility and a simpler approach to cyber risk management