CVE detail
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 6.1
Why it matters now
Mention timeline
- Total mentions
- 27
- within the 30d window
- Peak daily
- 8
- highest bucket
Evidence
Source links by recency
28 source links · newest first
- INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day ExploitSecurity Affairs
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since […]
newssecurityaffairs.comAug 4, 2026, 1:46 PM unding two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, Resecurity reports. Tracked as CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), the security defects allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and escalate their privileges to root. Patched on
newswww.securityweek.comAug 3, 2026, 10:39 AMgomery Vulnerabilities and Exploits Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410) Rapid7 Culture Rapid7 and Mindware Partner to Accelerate Cyber Resilience Across the Middle East Gopan Sivasankaran See all posts Get Started Command Platform Exposure Management MDR Services Solutions
vendorwww.rapid7.comJul 30, 2026, 3:14 PMgomery Vulnerabilities and Exploits Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410) Rapid7 Culture Rapid7 and Mindware Partner to Accelerate Cyber Resilience Across the Middle East Gopan Sivasankaran See all posts Get Started Command Platform Exposure Management MDR Services Solutions
vendorwww.rapid7.comJul 28, 2026, 1:00 PMlized AI Model for Vulnerability Hunting Check Point patches actively exploited SmartConsole authentication bypass flaw CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities cata
newssecurityaffairs.comJul 26, 2026, 11:42 AMWyman Vulnerabilities and Exploits Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410) Rapid7 Culture Rapid7 and Mindware Partner to Accelerate Cyber Resilience Across the Middle East Gopan Sivasankaran Detection and Response Security Teams Are Ready To Become More Preemptive. What’s Hold
vendorwww.rapid7.comJul 22, 2026, 1:28 PM- SonicWall SMA zero-days were exploited weeks before disclosureHelp Net Security
Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,
newswww.helpnetsecurity.comJul 21, 2026, 10:35 AM The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek .
newswww.securityweek.comJul 20, 2026, 2:11 PM- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News
on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo
newsthehackernews.comJul 20, 2026, 1:32 PM - 20th July – Threat Intelligence ReportCheck Point Research
day, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft Sha
vendorresearch.checkpoint.comJul 20, 2026, 12:18 PM Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks […]
newssecurityaffairs.comJul 20, 2026, 7:29 AMCVE-2026-15409 and CVE-2026-15410 are actively exploited SonicWall SMA1000 vulnerabilities that can be chained for unauthenticated system compromise. Learn how to validate exposure and verify remediation.
exploithorizon3.aiJul 17, 2026, 8:25 PM- Inc Ransomware Exploits SonicWall SMA Zero-DaysDark Reading
ecurity vendor SonicWall published a security advisory regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410. Together they could allow any random, unauthenticated attacker to gain remote code execution (RCE) powers and then run commands on the box at the root level. Indeed, this is already happening. Accord
newswww.darkreading.comJul 17, 2026, 8:01 PM and advance new models for human-machine collaboration ... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations Cyber Exposure Alerts Jul 15 2026 CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities… By Scott Caveza
vendorwww.tenable.comJul 16, 2026, 1:00 PMLinked URL: https://hellorecon.com/blog/cve-2026-15409 | Posted by slvnx | 2 points | 0 comments
communitynews.ycombinator.comJul 15, 2026, 6:53 PM- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildTenable
es secure remote access appliances which may have been chained for unauthenticated remote code execution. Key takeaways CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been
vendorwww.tenable.comJul 15, 2026, 5:14 PM ecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CVE-2026-15410 . The advisory urges customers to immediately apply the latest platform hotfix releases. Successful exploitation of CVE-2026-15409 permits an
vendorwww.rapid7.comJul 15, 2026, 4:19 PMs to help security teams improve cybersecurity maturity... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations AI Security Jul 16 2026 The best defenders build AI agents together: Join Tenable for Swarm at Black… By Nick Hayes Cyber Expos
vendorwww.tenable.comJul 15, 2026, 12:45 PM- U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
onicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient
newssecurityaffairs.comJul 15, 2026, 10:49 AM - SonicWall warns of active exploitation of two SMA 1000 zero-daysSecurity Affairs
ncidents indicating these vulnerabilities are being actively exploited in the wild. The first vulnerability, tracked as CVE-2026-15409 (CVSS score of 10.0), is a Server-side request forgery (SSRF) issue that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location. “A Server-side requ
newssecurityaffairs.comJul 15, 2026, 8:02 AM liances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to
newsthehackernews.comJul 15, 2026, 5:30 AMSonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek .
newswww.securityweek.comJul 15, 2026, 5:19 AMSonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]
newswww.bleepingcomputer.comJul 14, 2026, 9:23 PMNo excerpt available.
Mitigationwww.cisa.govJul 14, 2026, 8:16 PM- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008psirt.global.sonicwall.com
No excerpt available.
Vendor Advisorypsirt.global.sonicwall.comJul 14, 2026, 8:16 PM - SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)Help Net Security
SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise. If the outlin
newswww.helpnetsecurity.comJul 14, 2026, 5:40 PM ur new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient
governmentwww.cisa.govJul 14, 2026, 12:00 PMg NERC-CIP compliance, and implement robust security so... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations AI Security Jul 16 2026 The best defenders build AI agents together: Join Tenable for Swarm at Black… By Nick Hayes Cyber Expos
vendorwww.tenable.comJul 7, 2026, 6:30 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 3 stars
- Ch4120N/CVE-2026-15409High confidencegithubRepository topic discovery3 starsDiscovered Aug 3, 2026, 4:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-15410CVSS 7.2 · High
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific…
- CVE-2026-4116CVSS 7.2 · High
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
- CVE-2026-4114CVSS 6.6 · Medium
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
- CVE-2026-4113CVSS 7.2 · High
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
- CVE-2026-4112CVSS 7.2 · High
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only a…
- CVE-2025-40602CVSS 6.6 · Medium
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).