CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks
Brief
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SonicWall SMA1000 vulnerability, tracked as CVE-2026-15409 , to its Known Exploited Vulnerabilities (KEV) catalog after confirming exploitation in real-world attacks.
The flaw, a maximum-severity server-side request forgery (SSRF) bug, was weaponized as a zero-day alongside a second vulnerability affecting SonicWall secure remote-access appliances.
CVE-2026-15409 carries a CVSS score of 10. 0 and affects the SonicWall SMA1000 Appliance Workplace interface . Classified as CWE-918, the issue enables a remote, unauthenticated attacker to coerce a vulnerable appliance into making requests to unintended locations.
