Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 - CVE-2026-15409
Published: July 15, 2026 / Updated: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the appliance to make requests to unintended locations.
The vulnerability exists due to server-side request forgery in the SMA1000 Appliance Work Place interface when handling crafted requests. A remote attacker can send a specially crafted request to cause the appliance to make requests to unintended locations.
Active exploitation has been observed in the wild.
Affected software
How to mitigate CVE-2026-15409
Links to Public Exploits and PoC-codes
- Exploit #12964 - rapid7-CVE-2026-15409 (This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the websoc (August 21, 2026)
- Exploit #12888 - SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution (August 10, 2026)