First published · Last updated
CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
A server-side request forgery (SSRF) in SonicWall SMA1000 appliances can allow unauthenticated remote actors to cause the device to make requests to unintended locations. The source advises applying vendor mitigations and following CISA BOD 26-04 guidance or discontinuing the product if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 5/10
- Global importance
- 4/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Exploitation can cause appliances to make requests to unintended locations, so affected systems must be mitigated per CISA guidance.

