CVE-2026-15409

Published Jul 14, 2026

Last updated a month ago

Exploit knownCVSS critical 10.0
Sonicwall
Port (443)
Server
Network
Cloud
Zero-day
VPN
Netgear
Firmware

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-15409 is a critical server-side request forgery (SSRF) vulnerability impacting SonicWall SMA 1000 Series appliances. This flaw resides within the SMA1000 Appliance WorkPlace interface. Exploitation of CVE-2026-15409 can allow remote, unauthenticated attackers to compel the appliance to initiate requests to unintended network locations. This vulnerability has been observed in active exploitation, frequently in conjunction with CVE-2026-15410. SonicWall has released firmware patches to address this issue and advises customers to upgrade their appliances and investigate for potential compromise.

Description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Source
PSIRT@sonicwall.com
NVD status
Analyzed
Products
sma6210_firmware, sma7210_firmware, sma8200v

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Exploit added on
Jul 14, 2026
Exploit action due
Jul 17, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

PSIRT@sonicwall.com
CWE-918

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2026-15409 — CVSS 9.8 CRITICAL A critical vulnerability in GNU InetUtils telnetd can allow remote unauthenticated attackers to bypass authentication by supplying a crafted USER environme 🔎 Details: https://t.co/jMcKqGajkG #CVE #CyberSecurity #InfoSec #Telnet #Linu

    @stem__shop

    16 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA now records ransomware use against SonicWall SMA1000 flaws CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410. Exploitation predates the July hotfix, so a patched appliance is not a clean one. IoCs and reset steps: https://t.co/8Jewv7XSOZ https://t.co/QAcszEEX1q

    @CyberPulse_aus

    11 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Ransomware gangs exploited CVE-2026-15409 and CVE-2026-15410 to compromise SonicWall SMA1000 appliances, then moved laterally through corporate networks. Runtime segmentation could help contain post-compromise activity when perimeter devices are breached. #Ransomware #ZeroTrust

    @aviatrixtrc

    11 Aug 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 RANSOMWARE ALERT: CISA confirms ransomware gangs are now exploiting two SonicWall SMA1000 vulnerabilities tracked as CVE-2026-15409 and CVE-2026-15410. Attackers had already been exploiting the flaws as zero-days before SonicWall patched. https://t.co/uHgC46DmaR

    @CyberAlertsHQ

    10 Aug 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Resecurity informa que la operación de ransomware INC ha acelerado su actividad desde agosto, reclamando 885 víctimas. Los ataques explotan las vulnerabilidades CVE-2026-15409 y CVE-2026-15410 en dispositivos SonicWall SMA 1000, facilitando la… https://t.co/POTSjM1gvN https:

    @ProtAAPP

    8 Aug 2026

    234 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. INC Ransomware chains two SonicWall SMA 1000 zero-days CVE-2026-15409 CVE-2026-15410 CVSS 10.0 pre-authentication bypass root escalation active exploitation June 22. Multiple victims posted data leak site US Australia UAE Colombia Switzerland. WebSocket tunnel localhost services

    @Milwyn1

    7 Aug 2026

    66 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. Intel Report [CRITICAL] - Two critical zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances — CVE-2026-15409 (unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (post-authentication code injection, CVSS 7.2) —... https://t.co/5eNTiLPQB

    @EnigmaGlobalSW

    7 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 INC Ransomware chains SonicWall zero-days for ransomware The group exploited CVE-2026-15409 and CVE-2026-15410 to steal data and deploy ransomware. 🔗 read more: https://t.co/JEq4JVg0Im #ransomNews #cybersecurity

    @ransomnews

    6 Aug 2026

    472 Impressions

    4 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. New zero-days & CVEs threaten data in transit. Langflow RCE (CVE-2026-9198), SonicWall bypass (CVE-2026-15409), & Cisco FMC static creds (CVE-2026-20316) enable RCE/access, compromising privacy & integrity. Urgent patching vital. #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    5 Aug 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-nWj2Sy0 ( CVE-2026-42826 ) EGE-GH-FLy7Zaa ( CVE-2025-71338 ) EGE-GH-lPbsTBU ( CVE-2026-52887 ) EGE-GH-KAmy9Px ( CVE-2026-15409 ) EGE-GH-3TfhoOr ( CVE-2026-69083 ) ..🧵👇

    @exploitgrid

    5 Aug 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. مجموعة فدية تستغل ثغرتين صفريتين في بوابات الوصول الآمن لاختراق الشبكات. الثغرات : CVE-2026-15409 (10.0) + CVE-2026-15410 المنتج : SonicWall SMA1000 المهاجم : INC Ransomware الحل : v12.4.3-03

    @KasperskyDev

    5 Aug 2026

    270 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 1/ SonicWall SMA1000 zero day chain CVE-2026-15409 and CVE-2026-15410 is now the engine for INC Ransomware. Pre disclosure root access and MFA seed theft started in June. New victims keep appearing. Full report best on wide desktop screen. https://t.co/b6OknHtJvW

    @inferlume_hq

    4 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. Critical zero-days: SonicWall SMA 1000 (CVE-2026-15409/10) exploited by ransomware & FreeRDP TLS bypass (CVE-2026-66402) found. Immediate patching vital to safeguard data privacy/integrity in transit. #Cybersecurity #News

    @YourAnon_irc

    4 Aug 2026

    88 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. INC Ransomware is exploiting SonicWall SMA 1000 flaws tied to CVE-2026-15409 and CVE-2026-15410, targeting orgs across multiple countries to steal credentials, session data, and MFA seeds for persistent access. #SonicWall #INC_Ransomware #Japan https://t.co/XEGOUZPxC3

    @TweetThreatNews

    3 Aug 2026

    182 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. INC Ransomware is exploiting SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410, enabling remote access and root escalation. The flaws are now patched and listed in CISA's KEV catalog. #SonicWall #CISA #INC Ransomware https://t.co/8Jdwg2xqc6

    @TweetThreatNews

    3 Aug 2026

    184 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+. #SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533 https://t.co/hrbSA9av4u

    @Daily_CyberSec

    3 Aug 2026

    404 Impressions

    3 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 INC Ransomware Exploits SonicWall SMA Vulnerability Chain Resecurity reports that INC Ransomware is actively weaponizing two vulnerabilities affecting SonicWall SMA 1000 appliances. CVE-2026-15409 allows unauthenticated access to internal services, while CVE-2026-15410 can

    @XQOPTRX

    1 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. SonicWall SMA 1000 zero-day chain CVE-2026-15409 (CVSS 10.0) + CVE-2026-15410 (CVSS 7.2) weaponized by INC Ransomware, actively exploited since June 22, 2026, before patch release. Both CVEs are in CISA KEV. - CVE-2026-15409 is a pre-auth WebSocket proxy bypass: an attacker http

    @DFIR_Radar

    1 Aug 2026

    161 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild https://t.co/EdpLZ1K5pk https://t.co/RV39hONZ2R

    @ggrubamn

    28 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. ⚠️ Vulnerabilidades en productos SonicWall ❗ CVE-2026-15410 ❗ CVE-2026-15409 ➡️ Más info: https://t.co/DO9DnYoe1z https://t.co/7ZVIdgGJmY

    @CERTpy

    27 Jul 2026

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 CISA KEV: SonicWall SMA1000 Chained Zero-Day CVE-2026-15409 (CVSS 10.0) — SSRF CVE-2026-15410 (CVSS 7.2) — Code Injection Chained for unauthenticated RCE. Active exploitation confirmed. Patch by July 17. → https://t.co/KswwFtlBZa #cybersecurity #infosec #SonicWall

    @ThreatAft

    27 Jul 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Cyber Pulse 🛡️🦅 Inc ransomware group is actively exploiting two critical SonicWall SMA zero-days CVE-2026-15409 & CVE-2026-15410. Attackers gain full root access without any login. Many ships and ports still use SonicWall appliances for remote access. If you haven’

    @_Labzy

    26 Jul 2026

    97 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 CVE-2026-15409 / CVE-2026-15410 — SonicWall SMA1000 (zero-days, actively exploited)

    @onFafaNutifafa

    24 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. I mentioned two days ago that we are tracking INC Ransomware group are targeting Sonicwall CVE's (CVE-2026-15409 and CVE-2026-15410). We now see Scattered Spider (known RaaS "sub-contractor") pushing out how to find devices on the internet showcasing vulnerable devices. If ht

    @bcs_erictaylor

    24 Jul 2026

    96 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  25. We are now tracking the INC Ransomware group starting to target these two CVE's to gain access to your network. CVE: CVE-2026-15409 Vendor: SonicWall SMA1000 Appliances Vulnerability: Server-Side Request Forgery Vulnerability EPSS Lookup: https://t.co/66DJcVLBos CVE:

    @bcs_erictaylor

    22 Jul 2026

    118 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Attackers exploited SonicWall zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) to deploy custom malware, compromising SMA VPN appliances. Organizations must apply patches and monitor for suspicious activity to mitigate risks. #CyberSecurity #SonicWall #ZeroDay #Malware

    @dailytechonx

    21 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨 Critical Zero-Day Alert! Discover how threat actors chained SSRF & command injection (CVE-2026-15409 & CVE-2026-15410) in SonicWall SMA appliances to gain root access prior to disclosure. Read the full technical: https://t.co/KazCx2Qz6F #SonicWall #ZeroDay #CyberSe

    @denizhalilT

    21 Jul 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. SonicWall vulns actively exploited in zero-day attacks for weeks. Info, incl. fix info, now at #SecAlerts: CVE-2026-15409, CVSS 10: https://t.co/x8fNujr1aM CVE-2026-15410, CVSS 7.2: https://t.co/FmeSaTFAXB #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #SonicWall h

    @SecAlertsCo

    21 Jul 2026

    148 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. SonicWall SMA1000にゼロデイ 脆弱性、既にサイバー攻撃へ悪用(CVE-2026-15409, CVE-2026-15410)|セキュリティ対策Lab https://t.co/lowgTzDC5G "CVE-2026-15409はCVSSスコア10.0(最高深刻度)のSSRFの脆弱性で、SMA1000のWork Placeインターフェ

    @catnap707

    20 Jul 2026

    363 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Investigadores de Volexity han atribuido a un actor de amenazas no documentado la explotación de vulnerabilidades zero-day en dispositivos SonicWall SMA 1000 desde el 22 de junio de 2026. Las CVE-2026-15409 y CVE-2026-15410 permiten ejecución de… https://t.co/kFqROgOlcw http

    @ProtAAPP

    20 Jul 2026

    177 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. If you're looking into the newest SonicWall exploitation (CVE-2026-15409 & CVE-2026-15410), the Volexity blog is a must read: https://t.co/WBbKtroIGJ

    @tlansec

    20 Jul 2026

    2229 Impressions

    8 Retweets

    25 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  32. SonicWall SMA1000にゼロデイ 脆弱性既にサイバー攻撃へ悪用(CVE-2026-15409, CVE-2026-15410) https://t.co/ms8KLTtt3c #セキュリティ対策Lab #security #securitynews #cyberattack #脆弱性

    @securityLab_jp

    20 Jul 2026

    146 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🚨 Exploitation Alert: SonicWall SMA VPN Threat actors have been observed chaining two zero-day vulnerabilities in SonicWall SMA VPN appliances to achieve remote command execution and fully compromise affected devices. 🔴 CVE-2026-15409 — CVSS: 10.0 (Critical) 🔴 CVE-2026

    @RaoulBiasso

    20 Jul 2026

    27 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. sonicwall level 10 #ITSecurity vectors. Patch available, https://t.co/dWR54hu0Yt CVE-2026-15409 - A Server-side request forgery (SSRF) CVE-2026-15410 - Post-authentication improper control of generation of code ('Code Injection')

    @seaarepea

    19 Jul 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. SonicWall SMA Zero-Days: CVE-2026-15409 und CVE-2026-15410 werden aktiv von Inc Ransomware ausgenutzt. Sofort patchen! #ZeroDay #Ransomware https://t.co/W8OMN37dIY

    @wall_your_x

    19 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. CVE-2026-15409: Did SonicWall Fail to Prioritize Security Standards? https://t.co/s10MK2Voa3 #CyberSecurity #SonicWall #ZeroDayExploit

    @cyber_newsroom

    19 Jul 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 CISA KEV Deadlines This Week 📅 Jul 17: SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) + Code Injection (CVE-2026-15410) | Microsoft SharePoint Missing Auth (CVE-2026-56164, CVSS 9.8) 📅 Jul 18: Oracle E-Business Suite Improper Privilege Management (CVE-2026-46817,

    @techepages

    18 Jul 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Recent zero-day exploits (CVE-2026-15409, CVE-2026-15410) hit SonicWall SMA 1000, allowing unauthenticated SSRF & code injection. This enables internal network access, severely compromising data privacy and integrity in transit. #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    18 Jul 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Explotan vulnerabilidad 0-day de SonicWall SMA1000 SonicWall ha revelado dos vulnerabilidades en sus dispositivos de acceso remoto SMA1000 Series CVE-2026-15409 CVE-2026-15410 https://t.co/PStpRopym1

    @elhackernet

    18 Jul 2026

    1685 Impressions

    4 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Inc RansomwareがSonicWall SMAの脆弱性CVE-2026-15409及びCVE-2026-15410をゼロデイとして悪用している。Rapid7社報告。同社によると、厳密に使用された連鎖は不明だが、SSRFのCVE-2026-15409からコード実行を行い、CVE-2026-15410でr

    @__kokumoto

    18 Jul 2026

    849 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Volexity: UTA0533 exploited SonicWall SMA 1000 0-days (CVE-2026-15409, CVE-2026-15410) since June 2026 to achieve RCE and deploy malware. https://t.co/2l95mRkEKU

    @CTITraffic

    17 Jul 2026

    107 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. CVE-2026-15409 and CVE-2026-15410: SonicWall’s 0-Day Breach Exposes Serious Risk https://t.co/vVrVl3ikPV #Cybersecurity #CVE2026 #SonicWall

    @cyber_newsroom

    17 Jul 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨 Patch SonicWall SMA1000 now — CVE-2026-15409 (CVSS 10.0 SSRF) is being exploited in the wild, now in CISA's KEV. Also this week: CVE-2026-13001 (Podlove WP plugin RCE, 9.8), CVE-2026-14960 (Pegatron driver LPE, 9.8), MSFT Patch Tuesday. For more: https://t.co/ZUTqqMjQUp

    @exploitgrid

    17 Jul 2026

    50 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 🚨 Two SonicWall SMA1000 vulnerabilities. One dangerous attack chain. Rapid Response test now available for CVE-2026-15409 + CVE-2026-15410. https://t.co/URCUE1lc9D

    @Horizon3ai

    17 Jul 2026

    478 Impressions

    1 Retweet

    9 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  45. 🔹 ثغرتان صفريتان حرجتان في SonicWall SMA 1000 تُتيحان اختراقاً كاملاً. 🔸 أحدهما حصل على تصنيف 10.0 في CVSS. أعلنت SonicWall عن استغلال نشط للثغرتين CVE-2026-15409 وCVE-2026-15410 منذ

    @glitch4techs

    17 Jul 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  46. SonicWallのリモートアクセスVPN製品SMA1000シリーズで、実際の攻撃での悪用が確認された脆弱性2件が公表されました。利用者向けポータルのSSRF(CVE-2026-15409)は、認証不要で装置に意図しない宛先へ通信させら

    @MalwareBibleJP

    17 Jul 2026

    1088 Impressions

    2 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  47. CVE-2026-15409 (unauthenticated SSRF) and CVE-2026-15410 (post-auth code injection) in SonicWall SMA 1000 are chained in the wild, now on CISA KEV. #DFIR_Radar https://t.co/E3ewl4aFfr

    @DFIR_Radar

    17 Jul 2026

    184 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  48. ‼️ CVE-2026-15409: PoC exploit for CVE-2026-15409 that achieves non-root remote code execution on SonicWall SMA 1000 appliances. GitHub: https://t.co/j2ZEZLbDh8 https://t.co/kaYWnMbNkH

    @DarkWebInformer

    16 Jul 2026

    8719 Impressions

    16 Retweets

    45 Likes

    14 Bookmarks

    0 Replies

    1 Quote

  49. 🚨 CVE-2026-15409 (CVSS 10.0) & CVE-2026-15410: an unauthenticated SSRF chained with post-auth code injection in SonicWall SMA 1000 appliances, both under active exploitation. Full attack chain breakdown + remediation: https://t.co/tGPijFBcpA

    @colibrisec

    16 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Warning: #SonicWall #SMA1000 appliances are actively exploited! #CVE-2026-15409 and #CVE-2026-15410 lead to #SSRF and #RCE through code injection. IOCs and recommendations are available at: https://t.co/Nsgv57KXCq #Patch #Patch #Patch

    @CCBalert

    16 Jul 2026

    228 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations