CVE-2026-15409 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-15409 | CVSS 10.0 (Critical) | Exploit: PoC available
What Is It
CVE-2026-15409 is a server-side request forgery vulnerability in the SonicWall SMA1000 Appliance Work Place interface affecting SonicWall SMA6210 Firmware, SMA6210, and SMA7210 Firmware.
Technical Detail
The flaw could allow a remote unauthenticated attacker to cause a vulnerable appliance to send requests to unintended locations. An attacker may be able to supply or influence a request destination through the Work Place interface, causing the appliance to access internal services or other network resources reachable from the appliance. The available information does not confirm whether the issue enables direct remote code execution, credential disclosure, or access to specific internal endpoints.
Exploitation Status
A proof of concept is available. CVE-2026-15409 is not listed in CISA's Known Exploited Vulnerabilities Catalog, and active exploitation in the wild has not been confirmed.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize applying SonicWall updates or vendor-provided mitigations for affected SMA6210 and SMA7210 deployments as soon as they are available. Restrict administrative and Work Place interface access to trusted networks, VPN users, or tightly controlled allowlists where operationally feasible. Review appliance and network telemetry for unexpected outbound connections originating from SMA appliances, especially requests to internal management interfaces, cloud metadata services, loopback addresses, private address ranges, or other restricted network destinations. No CISA KEV remediation deadline applies at this time.