Skip to main content
Change Risk Intel

CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CVSS
8.6 (High)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — SMA1000 is internet-facing remote access; patch within one week and monitor management-plane logs in the interim.
Affected products
SonicWall SMA1000 Appliances

Why this one matters to a CAB

SonicWall SMA1000 is a remote-access gateway — by definition internet-facing, by definition trusted for VPN termination. A server-side request forgery in the appliance’s HTTP layer lets an unauthenticated attacker turn the appliance into a proxy into your internal network. That is worse than an unauthenticated RCE on a non-perimeter box, because the attacker inherits the appliance’s network position.

Defender’s angle

  • Interim block: SonicWall’s advisory names specific request paths. Add a WAF rule (or the SMA’s own web-firewall policy) to deny those paths from unauthenticated sources until the firmware update is deployed.
  • Log everything: enable full HTTPS access logging on the SMA before the change window. Because the exploit is unauthenticated, you will not see it in login records — it lives in the raw web access log.
  • Rotate saved connections: after patching, force a client bookmark refresh for every SMA user. An attacker who staged the SSRF pre-patch may have collected internal URLs that should now be considered known-adversary.

What to bring to CAB

A dual-stack change record: SMA1000 firmware upgrade plus the associated NetExtender client push. Include a business-hours communication because SMA restarts drop active tunnels.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.