Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-15409

Published 2026-07-14
Updated 2 months ago
Vendor/s
SonicWall
Product/s
SMA1000 Appliances
Version/s
12.4.3-03245
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-15409 is a critical SSRF vulnerability (CVSS 10.0) in SonicWall SMA1000 appliances actively exploited in the wild. Patch immediately.

CPE

SonicWall logo
SonicWall
Product Version Start Version End (excl.) Status
sma6210_firmware 12.4.3-03245 12.4.3-03245 vulnerable
sma6210_firmware 12.4.3-03387 12.4.3-03387 vulnerable
sma6210_firmware 12.4.3-03434 12.4.3-03434 vulnerable
sma6210_firmware 12.5.0-02283 12.5.0-02283 vulnerable
sma6210_firmware 12.5.0-02624 12.5.0-02624 vulnerable
sma6210_firmware 12.5.0-02800 12.5.0-02800 vulnerable
sma6210 - - unaffected
sma7210_firmware 12.4.3-03245 12.4.3-03245 vulnerable
sma7210_firmware 12.4.3-03387 12.4.3-03387 vulnerable
sma7210_firmware 12.4.3-03434 12.4.3-03434 vulnerable
sma7210_firmware 12.5.0-02283 12.5.0-02283 vulnerable
sma7210_firmware 12.5.0-02624 12.5.0-02624 vulnerable
sma7210_firmware 12.5.0-02800 12.5.0-02800 vulnerable
sma7210 - - unaffected
sma8200v 12.4.3-03245 12.4.3-03245 vulnerable
sma8200v 12.4.3-03387 12.4.3-03387 vulnerable
sma8200v 12.4.3-03434 12.4.3-03434 vulnerable
sma8200v 12.5.0-02283 12.5.0-02283 vulnerable
sma8200v 12.5.0-02624 12.5.0-02624 vulnerable
sma8200v 12.5.0-02800 12.5.0-02800 vulnerable
sma8200v - - unaffected

Related weakness (CWE)

CWE-918

Remediation plan

1

Apply official patches

SonicWall has released urgent firmware updates to address this SSRF vulnerability. Administrators should immediately visit the SonicWall support portal to download and install the latest security patches for the SMA 1000 series.

2

Update affected systems

Ensure all SMA 6210, 7210, and 8200v appliances are upgraded from vulnerable firmware versions, specifically those in the 12.4.3-03xxx and 12.5.0-02xxx series, to the recommended fixed versions provided by the vendor.

3

Restrict access

Limit access to the SMA Work Place interface to trusted IP addresses only. Implement strict egress filtering on the appliance to prevent it from initiating unauthorized connections to internal resources or suspicious external domains.

4

Monitor for exploitation

Conduct a forensic triage as per CISA BOD 26-04 guidelines. Review appliance logs for unusual outbound traffic patterns, specifically requests originating from the Work Place interface directed toward internal metadata services or private IP ranges.

Detection Guidance

"Detection should focus on identifying abnormal outbound HTTP/HTTPS requests originating from the SMA1000 appliance. Monitor web server logs for requests to the 'Work Place' interface containing suspicious URL parameters or IP addresses in the payload. Look for indicators of lateral movement, such as the appliance attempting to communicate with internal management interfaces (e.g., 169.254.169.254 or internal database ports) that it typically does not access."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management