Summary
CVE-2026-15409 is a critical Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in the SonicWall SMA1000 Appliance Work Place interface, carrying a maximum CVSS v3.1 base score of 10.0. A remote, unauthenticated attacker can exploit this flaw to cause the appliance to issue requests to unintended internal or external locations, effectively weaponizing the internet-facing device as a proxy to reach otherwise inaccessible network segments. SonicWall has confirmed active exploitation in the wild and CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026, with a mandatory remediation deadline of July 17, 2026.
Technical details
- Root cause: A Server-Side Request Forgery flaw (CWE-918) in the SMA1000 Work Place web interface — a component intentionally exposed to the internet for remote user access — allows attacker-controlled input to determine the target of outbound HTTP requests issued by the appliance itself.
- Trigger conditions: No authentication or user interaction is required. The vulnerability is directly reachable over HTTPS from the internet.
- Attack vector: Network —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N— zero complexity, no credentials, no prior access needed. - Impact: By abusing the appliance as a server-side proxy, an attacker can reach internal services and hosts behind the network perimeter that are otherwise inaccessible from the internet. CVSS scope is Changed (S:C), with High ratings across Confidentiality, Integrity, and Availability, reflecting the ability to pivot into internal infrastructure, exfiltrate data, and disrupt services far beyond the vulnerable component itself.
- Exploitation status: Actively exploited in the wild as a zero-day. SonicWall has confirmed multiple incidents. CVE-2026-15409 is being chained in coordinated attacks with CVE-2026-15410, a code injection vulnerability (CVSS 7.2) in the SMA1000 Appliance Management Console that enables authenticated OS command execution — together forming a full unauthenticated-to-RCE attack chain.
Affected software
SonicWall SMA1000 series appliances (SMA 6210, SMA 7210, SMA 8200v) running the following firmware versions:
- 12.4.x branch: 12.4.3-03245 through 12.4.3-03434 (inclusive)
- 12.5.x branch: 12.5.0-02283 through 12.5.0-02800 (inclusive)
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate patch: Upgrade to firmware 12.4.3-03453 (for 12.4.x deployments) or 12.5.0-02835 (for 12.5.x deployments). Patched builds are available on mysonicwall.com.
- SonicWall advises all customers to review appliance logs for indicators of compromise, reset all TOTP tokens, and change all user and administrator passwords following remediation.
- SonicWall has stated that patching alone is not sufficient if active compromise is detected. In that case, hardware appliances should be re-imaged and virtual appliances fully redeployed.
- CISA’s BOD 26-04 requires U.S. federal agencies to apply vendor mitigations by July 17, 2026. All organizations with internet-exposed SMA1000 appliances should treat this timeline as an urgent benchmark regardless of federal mandate.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

