CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
- CVSS
- 8.6 (High)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — SMA1000 is internet-facing remote access; patch within one week and monitor management-plane logs in the interim.
- Vendor advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- Affected products
- SonicWall SMA1000 Appliances
Why this one matters to a CAB
SonicWall SMA1000 is a remote-access gateway — by definition internet-facing, by definition trusted for VPN termination. A server-side request forgery in the appliance’s HTTP layer lets an unauthenticated attacker turn the appliance into a proxy into your internal network. That is worse than an unauthenticated RCE on a non-perimeter box, because the attacker inherits the appliance’s network position.
Defender’s angle
- Interim block: SonicWall’s advisory names specific request paths. Add a WAF rule (or the SMA’s own web-firewall policy) to deny those paths from unauthenticated sources until the firmware update is deployed.
- Log everything: enable full HTTPS access logging on the SMA before the change window. Because the exploit is unauthenticated, you will not see it in login records — it lives in the raw web access log.
- Rotate saved connections: after patching, force a client bookmark refresh for every SMA user. An attacker who staged the SSRF pre-patch may have collected internal URLs that should now be considered known-adversary.
What to bring to CAB
A dual-stack change record: SMA1000 firmware upgrade plus the associated NetExtender client push. Include a business-hours communication because SMA restarts drop active tunnels.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.