CVE-2026-15409
published 2026-07-14CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could…
PriorityP199critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-17
Exploited in the wild
EPSS
78.44%
99.5th percentile
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sonicwall | sma1000 | 12.4.3-03245 – 12.4.3-03434 | — |
| sonicwall | sma1000 | 12.5.0-02283 – 12.5.0-02800 | — |
| sonicwall | sma6210_firmware | — | — |
| sonicwall | sma6210_firmware | — | — |
| sonicwall | sma6210_firmware | — | — |
| sonicwall | sma6210_firmware | — | — |
| sonicwall | sma6210_firmware | — | — |
| sonicwall | sma6210_firmware | — | — |
| sonicwall | sma7210_firmware | — | — |
| sonicwall | sma7210_firmware | — | — |
| sonicwall | sma7210_firmware | — | — |
| sonicwall | sma7210_firmware | — | — |
| sonicwall | sma7210_firmware | — | — |
| sonicwall | sma7210_firmware | — | — |
| sonicwall | sma8200v | — | — |
| sonicwall | sma8200v | — | — |
| sonicwall | sma8200v | — | — |
| sonicwall | sma8200v | — | — |
| sonicwall | sma8200v | — | — |
| sonicwall | sma8200v | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandcsrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&command=rollback&rollbackUpgradeTime=&hotfix=../../../../../tmp/1234.sh&rollbackHotfixTime=↗
- →Hunt ctrl-service.log for invocations of the hotfix-removal utility with path traversal sequences (e.g., '../../') pointing to shell scripts in /tmp — indicative of CVE-2026-15410 exploitation. ↗
- →Alert on /var/lib/unit/conf.json containing routes for /__api__/login or /__api__/logout, as these URIs do not exist in legitimate SMA1000 configuration and indicate post-exploitation tampering. ↗
- →Monitor extraweb_access.log for HTTP 200 responses to /__api__/login or /__api__/logout as an indicator of compromise. ↗
- →The Erlang cookie used for unauthenticated RCE via the SSRF tunnel to localhost:1050 is hardcoded; detect use of the value '10ecad5b446e86864832904cd439b6b70262' in network traffic to port 1050. ↗
- →Flag WebSocket upgrade requests (HTTP 101) to /wsproxy with the User-Agent 'SMA Connect Agent' from external/untrusted sources as a strong exploitation indicator. ↗
- →Monitor for access to /tmp/temp.db* on the SMA1000 appliance, consistent with theft of stored session data. ↗
- →Detect pre-exploitation reconnaissance via repeated requests to /auth1.html, /.env, and /api/sonicos/is-sslvpn-enabled against internet-facing SMA1000 appliances. ↗
- ·CVE-2026-15409 and CVE-2026-15410 do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line — scope detection and remediation only to SMA1000 Series appliances. ↗
- ·For CVE-2026-15410 path traversal, the system only reboots (and executes the payload) if the referenced hotfix file actually exists on disk; a missing file results in no reboot and no execution, which may affect forensic interpretation of reboot events. ↗
- ·There are no workarounds available for these vulnerabilities; patching to the fixed platform-hotfix versions is the only remediation. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
cisa·2026-07-14·CVSS 10.0
CVE-2026-15409 [CRITICAL] CWE-918 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Vulnerability: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Affected: SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adh
GHSA
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
ghsa_unreviewed·2026-07-14
CVE-2026-15409 [CRITICAL] CWE-918 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
VulnCheck
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
vulncheck·2026·CVSS 10.0
CVE-2026-15409 [CRITICAL] CWE-918 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Affected: SonicWall SMA1000 Appliances
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD
No detection rules found.
Nuclei
SonicWall SMA1000 - Server-Side Request Forgery
nuclei·CVSS 10.0
CVE-2026-15409 [CRITICAL] SonicWall SMA1000 - Server-Side Request Forgery
SonicWall SMA1000 - Server-Side Request Forgery
SMA1000 Appliance Work Place interface contains a server side request forgery caused by improper request validation, letting remote unauthenticated attackers make requests to unintended locations, exploit requires no special privileges.
Template:
id: CVE-2026-15409
info:
name: SonicWall SMA1000 - Server-Side Request Forgery
author: DhiyaneshDk,rapid7
severity: critical
description: |
SMA1000 Appliance Work Place interface contains a server side request forgery caused by improper request validation, letting remote unauthenticated attackers make requests to unintended locations, exploit requires no special privileges.
impact: |
Remote attackers can make the appliance send requests to unintended locations, potentially accessing internal reso
Checkpoint
20th July – Threat Intelligence Report
blogs_checkpoint·2026-07-20
CVE-2026-56164 20th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance.
Jscrambler,
Tenable
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
blogs_tenable·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
## wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.
## Key takeaways:
Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations.
Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing w
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Hackernews
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
blogs_hackernews·2026-07-19·CVSS 10.0
CVE-2026-15409 [CRITICAL] SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moniker UTA0533 . The discovery was made following an incident response investigation earlier this month. The impacted organization has not been identified.
"This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWa
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Tenable
The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
blogs_tenable·2026-07-16
CVE-2026-32201 The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
## The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries together.
## Key takeaways
According to Gartner®, by 2028, an average global Fortune 500 enterprise will have more than 150,000 AI agents in use, up from less than 15 in 2025, generating significant agent sprawl, IT complexity, and management challenges. 1
Security practitioners are building their own agentic, open-source tooling to cut out hours of manual phishing email triage, accelerate threat hunts, and uplevel junior ta
Tenable
Understanding Claude Tag’s access model in Slack and how to configure it securely
blogs_tenable·2026-07-15
CVE-2026-15409 Understanding Claude Tag’s access model in Slack and how to configure it securely
## Understanding Claude Tag’s access model in Slack and how to configure it securely
Anthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it.
## Key takeaways
Claude Tag, Anthropic’s newly launched AI agent for Slack, acts on connected services using shared credentials an admin configures for a workspace or for a specific private channel, not the credentials of the user tagging it.
Claude Tag uses the service-identity pattern, like deploy bots, workflow automations, and incoming webhooks, rather than per-user OAuth delegation. As a result, one admin-configured bundle serves everyone in the channel.
Inviting someone to a channel wh
Rapid7
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
blogs_rapid7·2026-07-15·CVSS 10.0
CVE-2026-15409 [CRITICAL] Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
## Overview
On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CVE-2026-15410 . The advisory urges customers to immediately apply the latest platform hotfix releases.
Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based re
Tenable
5 reasons to bring application security data into your exposure management platform
blogs_tenable·2026-07-15
CVE-2026-15409 5 reasons to bring application security data into your exposure management platform
## 5 reasons to bring application security data into your exposure management platform
When you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate together.
## Key takeaways
Break application security silos and obtain full code-to-runtime visibility by integrating standalone code scanner data with your exposure management platform.
By contextualizing application security findings, filtering out alert noise, and automating patches, exposure management helps organizations pinpoint and fix the riskiest coding flaws to your organization.
Leveraging exposure management, CI
Hackernews
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
blogs_hackernews·2026-07-15·CVSS 10.0
CVE-2026-15409 [CRITICAL] Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
The vulnerabilities are listed below -
CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location.
CVE-2026-15410 (CVSS score: 7.2) - A post-authentication code injection vulnerability r
Tenable
CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
blogs_tenable·2026-07-15·CVSS 10.0
CVE-2026-15409 [CRITICAL] CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
## CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.
## Key takeaways
CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances.
Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall.
Patches and indicators of compromise are available and urgent patching is recommended.
## Background
SonicWall's Secure Mobile Access (SMA) 1000 Series appliances are enterprise-grade SSL VPN gateways which serve
2026-07-14
Published
2026-07-14
Added to CISA KEV
Exploited in the wild