SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVE-2026-15409 is a server-side request forgery (CWE-918) flaw in the Work Place interface of SonicWall SMA1000 appliances (models 6210, 7210, and 8200v). In SSRF, the server fails to validate attacker-supplied URL or host parameters before using them to construct outbound requests. Because the SMA1000 sits at the network perimeter with privileged access to internal segments, the appliance's trust context makes it a particularly effective relay: requests it issues may reach internal services that would otherwise be unreachable from the internet. No authentication is required to reach the vulnerable interface.
An unauthenticated remote attacker sends a crafted HTTP request to the Work Place interface, specifically to the /wsproxy endpoint, supplying a malicious host parameter. The appliance issues a server-side request to the attacker-chosen destination, potentially probing internal network services, bypassing firewall controls, or relaying requests through the appliance's trusted network position. SonicWall PSIRT has confirmed active exploitation across multiple investigated cases. This vulnerability is associated with known ransomware use, making rapid remediation a priority. The vendor advisory notes no workaround exists; patching is the only fix.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If SonicWall SMA1000 Appliances runs inside your authorization boundary, CVE-2026-15409 directly affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog with a remediation deadline of July 17, 2026. An unpatched KEV within your boundary is an assessor finding — one you must either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it.
Remediating SonicWall SMA1000 Appliances is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to help you document the fix for your next assessment. The remediation work is yours to execute; maintaining a compliant posture while you do it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-15409 surfaces, exposure is identified through continuous monitoring rather than surfacing only when an assessor flags it during a scheduled review.
Book a meeting and Knox maps your path to authorization: FedRAMP in 90 days for 90% less, without the delays or dependencies that define the traditional process.
If CVE-2026-15409 is not remediated by July 17, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









