SonicWall SMA1000 bug can let attackers redirect appliance requests

Published July 14, 2026 CVE-2026-15409

A flaw in SonicWall SMA1000 appliances lets attackers trick the device into sending requests to their own servers instead of the intended ones. This can let them steal data or redirect users to fake sites.

Severity
CriticalCVSS 3.1 · 10.0
Fix
Not confirmedLast checked on Sep 4, 2026
Affected versions
12.4.3-03245 through 12.4.3-03434; 12.5.0-02283 through 12.5.0-02800
Weakness
CWE-918Server-Side Request Forgery (SSRF)
Exploit likelihood
85% in 30 daysEPSS, higher than 100% of known flaws
Affects
SMA1000
Exploited
Yes, in the wildListed by CISA, used in ransomware
Added to CISA list
Jul 14, 2026
Federal fix deadline
Jul 17, 2026

How it works

An attacker sends a specially crafted request to the SMA1000's web interface that forces it to send its own requests to a server controlled by the attacker instead of the real destination.

What to do

Check whether the installed SonicWall SMA1000 version is older than the fixed version in the vendor advisory or current release.

Update to the latest firmware version from SonicWall's support site. Restart the appliance after updating to apply changes.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 appliances (CVE-2026-15409) allows attackers to manipulate the appliance's internal network requests. By sending specially crafted inputs, an attacker could force the device to send requests to arbitrary internal or external servers, potentially exposing sensitive backend systems or redirecting traffic to malicious endpoints. This could enable further attacks, such as data exfiltration or lateral movement within a network.

The flaw affects SonicWall SMA1000 appliances and was added to CISA's KEV Catalog due to active exploitation. No fixed version was disclosed in the source.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator