Knox CVE Database
/
CVE-2026-15409
Critical
10.0
Ransomware use

CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Added to the CISA KEV catalog:
July 14, 2026

Overview

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Vulnerability details

Affected vendor
SonicWall
Affected product
SMA1000 Appliances
Weakness type (CWE)
CWE-918

CVE-2026-15409 is a server-side request forgery (CWE-918) flaw in the Work Place interface of SonicWall SMA1000 appliances (models 6210, 7210, and 8200v). In SSRF, the server fails to validate attacker-supplied URL or host parameters before using them to construct outbound requests. Because the SMA1000 sits at the network perimeter with privileged access to internal segments, the appliance's trust context makes it a particularly effective relay: requests it issues may reach internal services that would otherwise be unreachable from the internet. No authentication is required to reach the vulnerable interface.


An unauthenticated remote attacker sends a crafted HTTP request to the Work Place interface, specifically to the /wsproxy endpoint, supplying a malicious host parameter. The appliance issues a server-side request to the attacker-chosen destination, potentially probing internal network services, bypassing firewall controls, or relaying requests through the appliance's trusted network position. SonicWall PSIRT has confirmed active exploitation across multiple investigated cases. This vulnerability is associated with known ransomware use, making rapid remediation a priority. The vendor advisory notes no workaround exists; patching is the only fix.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review extraweb_access.log for requests to /wsproxy with unexpected or external host parameters returning HTTP 101 status; legitimate WebSocket upgrades should target known, configured internal destinations only.
  • Inspect /var/lib/unit/conf.json for routes referencing /api/login or /api/logout; these URIs do not exist in legitimate SMA1000 configuration and indicate post-exploitation tampering.
  • Check ctrl-service.log for hotfix rollback entries containing path traversal sequences, which the vendor advisory identifies as a distinct indicator of compromise on affected appliances.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 17, 2026

Additional hardening

  • Restrict access to the SMA1000 Work Place interface at the network perimeter to known, authorized source IP ranges; internet-wide exposure significantly increases exploitation risk.
  • Segment the SMA1000 from sensitive internal subnets so that appliance-originated requests cannot reach high-value internal services even if SSRF is triggered.
  • If IOCs are confirmed in logs, re-image hardware appliances or redeploy virtual instances, rotate all user and administrator credentials, and reset TOTP tokens before returning the device to service.
  • Conduct forensic triage of extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json before patching to preserve evidence of any prior compromise, as the vendor and CISA both require forensic review.

Key dates

Published (NVD)
July 14, 2026
Added to CISA KEV
July 14, 2026
Remediation deadline
July 17, 2026
Last updated
July 16, 2026

References

Frequently asked questions

Does CVE-2026-15409 affect my FedRAMP authorization?

If SonicWall SMA1000 Appliances runs inside your authorization boundary, CVE-2026-15409 directly affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog with a remediation deadline of July 17, 2026. An unpatched KEV within your boundary is an assessor finding — one you must either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it.

How does Knox help me handle CVE-2026-15409?

Remediating SonicWall SMA1000 Appliances is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to help you document the fix for your next assessment. The remediation work is yours to execute; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-15409 surfaces, exposure is identified through continuous monitoring rather than surfacing only when an assessor flags it during a scheduled review.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path to authorization: FedRAMP in 90 days for 90% less, without the delays or dependencies that define the traditional process.

What happens if CVE-2026-15409 isn't remediated by July 17, 2026?

If CVE-2026-15409 is not remediated by July 17, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting