Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-15409: SonicWall SMA1000 Appliances Can Make Unwanted Internet Requests

Known exploited
CVE-2026-15409 CVE-2026-15409 CVE-2026-15409
Summary

A security issue in SonicWall SMA1000 Appliances could allow an attacker to trick the device into accessing unauthorized websites or services. This could potentially lead to data theft or other malicious activities. We recommend updating the appliance to the latest software version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
sonicwall sma1000 appliances All versions
sonicwall sma1000 <= 12.4.3-03434
sonicwall sma6210_firmware 12.4.3-03245
12.4.3-03387
12.4.3-03434
12.5.0-02283
12.5.0-02624
12.5.0-02800
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:*
sonicwall sma7210_firmware 12.4.3-03245
12.4.3-03387
12.4.3-03434
12.5.0-02283
12.5.0-02624
12.5.0-02800
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03245:*:*:*:*:*:*:*
sonicwall sma8200v 12.4.3-03245
12.4.3-03387
12.4.3-03434
12.5.0-02283
12.5.0-02624
12.5.0-02800
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:*
Original title
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Original description
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026