Exploited Vulnerabilities Daily
🌐 English

Home › SonicWall

CVE-2026-15409: SonicWall SMA1000 Appliances

EPSS6.7%No. 1368 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV19
Same product5
FieldValue
VendorSonicWall
ProductSMA1000 Appliances
NameSonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Added to KEV2026-07-14
US federal due date2026-07-17
Ransomware useKnown
CWECWE-918

CISA description

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-83549SonicWall SMA1000 Appliances2026-09-0210.7%Unknown
CVE-2026-83548SonicWall SMA1000 Appliances2026-09-028.7%Unknown
CVE-2026-15410SonicWall SMA1000 Appliances2026-07-1411.7%Known
CVE-2025-23006SonicWall SMA1000 Appliances2025-01-2423.4%Known

NVD — CVE-2026-15409

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A SonicWall SMA1000 Appliances vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14.