Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-15409 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-15409 | CVSS 10.0 (Critical) | Exploit: PoC available

What Is It

CVE-2026-15409 is a server-side request forgery vulnerability in the SonicWall SMA1000 Appliance Work Place interface affecting SonicWall SMA6210 Firmware, SMA6210, and SMA7210 Firmware.

Technical Detail

The flaw could allow a remote unauthenticated attacker to cause a vulnerable appliance to send requests to unintended locations. An attacker may be able to supply or influence a request destination through the Work Place interface, causing the appliance to access internal services or other network resources reachable from the appliance. The available information does not confirm whether the issue enables direct remote code execution, credential disclosure, or access to specific internal endpoints.

Exploitation Status

A proof of concept is available. CVE-2026-15409 is not listed in CISA's Known Exploited Vulnerabilities Catalog, and active exploitation in the wild has not been confirmed.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize applying SonicWall updates or vendor-provided mitigations for affected SMA6210 and SMA7210 deployments as soon as they are available. Restrict administrative and Work Place interface access to trusted networks, VPN users, or tightly controlled allowlists where operationally feasible. Review appliance and network telemetry for unexpected outbound connections originating from SMA appliances, especially requests to internal management interfaces, cloud metadata services, loopback addresses, private address ranges, or other restricted network destinations. No CISA KEV remediation deadline applies at this time.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →