
CVE-2026-15409
Critical Server-Side Request Forgery (SSRF) vulnerability affecting SonicWall SMA1000 Series appliances.
This repository documents the vulnerability, affected products, technical overview, impact, detection guidance, and remediation.
CVE-2026-15409 is a critical unauthenticated Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 Series appliances.
The flaw allows a remote attacker to force the appliance to perform unintended HTTP requests to internal or external resources. According to public advisories, the vulnerability has been exploited in real-world attacks and may be chained with additional vulnerabilities for further compromise.
| Product | Status |
|---|---|
| SonicWall SMA1000 Series | Vulnerable |
| SMA6210 | Vulnerable |
| SMA7210 | Vulnerable |
| SMA8200v | Vulnerable |
Successful exploitation may allow attackers to:
Internet
│
▼
Attacker
│
▼
SonicWall SMA1000
│
▼
Unexpected Internal HTTP Requests
│
▼
Internal Services / Cloud Metadata / Management Interfaces
Security teams should monitor for:
.
├── README.md
├── assets
│ └── banner.png
├── docs
│ ├── overview.md
│ ├── timeline.md
│ └── mitigation.md
└── LICENSE
This repository is intended solely for defensive security, research, and educational purposes. It does not include exploit code or instructions for unauthorized access. Users are responsible for complying with applicable laws and organizational policies.
Consider giving it a Star ⭐ to support cybersecurity research.
Stay Secure • Patch Early • Monitor Continuously
| Field | Value |
|---|
| CVE ID | CVE-2026-15409 |
| Severity | Critical |
| CVSS v3.1 | 10.0 |
| Attack Vector | Network |
| Authentication | None |
| User Interaction | Not Required |
| Type | Server-Side Request Forgery (SSRF) |
| Impact | Internal resource access, attack chaining |
| Metric |
|---|
| Rating |
|---|
| Severity | 🔴 Critical |
| Exploitability | ⭐⭐⭐⭐⭐ |
| Authentication | None |
| Complexity | Low |
| Public Awareness | High |
| Patch Available | ✅ Yes |