NopSec.com uses cookies to make interactions with the Company’s Websites easy and meaningful. When you visit one of the Company’s Websites, NopSec.com’s servers send a cookie to your computer. Standing alone, cookies do not personally identify you; they merely recognize your Web browser. Unless you choose to identify yourself to NopSec.com, either by responding to a promotional offer, opening an account, or filling out a Web form (such as a “Contact Us” or a “Free Trial” Web form), you remain anonymous to the Company. Please go to our privacy statement for details.

What is CVE-2026-15409?

Multi-color grid abstract

CVE-2026-15409, also known as the SonicWall SMA1000 Server-Side Request Forgery (SSRF) flaw, is a critical security vulnerability affecting enterprise secure remote access gateways. The flaw was discovered by Adam Babis of SonicWall PSIRT. It was observed in zero-day attacks in July 2026, and allows unauthenticated attackers to bypass perimeter controls.

Key aspects of the vulnerability

Attack Mechanism:
The flaw resides within the WebSocket proxy feature (/wsproxy) of the “SonicWall WorkPlace” web application interface. An unauthenticated remote attacker can pass malicious URL parameters containing a targeted hostname (such as localhost or loopback IP addresses). This forces the appliance to establish a netcat-like TCP tunnel to local, isolated system services running behind the firewall that should otherwise be inaccessible.

Impact:
Successful exploitation permits unauthenticated attackers to query internal appliance services. In observed attacks, this vulnerability is frequently chained with CVE-2026-15410 to achieve remote code execution as root, allowing threat actors to harvest session tokens, steal TOTP seeds, and establish a stealthy backdoor for lateral network movement.

Mitigation:
SonicWall released emergency hotfixes and firmware upgrades on July 14, 2026, to neutralize the vulnerability. The official updates validate and restrict user-supplied parameters passed to the /wsproxy endpoint.

Because attackers may have already harvested credentials or established persistence prior to patching, administrators must explicitly audit system logs for indicators of compromise (IOCs) rather than relying solely on the firmware upgrade.

How bad is this?

According to the National Vulnerability Database (NVD) and initial vendor advisories, CVE-2026-15409 has a CVSS v3.x Base Score of 10.0 (CRITICAL) and is categorized under CWE-918 Server-Side Request Forgery (SSRF).

  • Severity: Critical
  • No authentication required
  • Active exploitation in the wild (CISA KEV listed)

Who is affected by this?

Product:
SonicWall Secure Mobile Access (SMA) 1000 Series (Models: SMA6210, SMA7210, and SMA8200v)

Affected Firmware Versions:

  • 12.4.3-03245
  • 12.4.3-03387
  • 12.4.3-03434 (platform-hotfix)
  • 12.5.0-02283
  • 12.5.0-02624
  • 12.5.0-02800 (platform-hotfix)

How is it exploited?

This vulnerability is exploited remotely over port 443 by sending a specifically crafted HTTP/WebSocket request containing an unauthorized target destination parameter to the /wsproxy pathway. It requires no prior credentials or user interaction.

How do I protect myself?

Deploy the latest official firmware releases (such as 12.4.3-03453, 12.5.0-02835, or higher) immediately. If your organization cannot patch immediately, restrict inbound access to the SMA WorkPlace login interface to trusted IP addresses only.

Mitigating factors?

There are no built-in mitigating factors that eliminate the risk if the WorkPlace interface is exposed directly to the public internet. If exploitation is detected via log analysis (e.g., unexpected requests returning HTTP 101 switching protocols on the WebSocket path), organizations must execute an incident response plan. This includes re-imaging physical hardware, resetting all administrator/user corporate passwords, and rotating active multi-factor authentication (MFA) TOTP secret seeds.

Additional Resources

Schedule a Product Demo Today!

See how NopSec's security insights and cyber thread exposure management system platform can organize your security chaos.

New Case Study: When Cyber Risk Is Financial Risk

X