【Vulnerability Alert】SonicWall SMA1000 Series Products Contain a Critical Cybersecurity Vulnerability (CVE-2026-15409)
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026071601075757 | Publication Time | 2026-07-16 13:13:58 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-07-16 13:13:58 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】SonicWall SMA1000 Series Products Contain a Critical Cybersecurity Vulnerability (CVE-2026-15409) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000007 SonicWall issued an announcement regarding a critical cybersecurity vulnerability affecting its SMA1000 series products (CVE-2026-15409, CVSS: 10.0). This is an SSRF vulnerability that exists in the appliance work interface of SMA1000 series products. An unauthenticated remote attacker may issue unintended requests. Note: SonicWall PSIRT has currently investigated multiple cases indicating that this vulnerability is being actively exploited. It is recommended that temporary mitigation measures be implemented as soon as possible to prevent potential attacks targeting this vulnerability. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
SMA 1000 Series products versions 12.4.3-03245 to 12.4.3-03434 (inclusive) SMA 1000 Series products versions 12.5.0-02283 to 12.5.0-02800 (inclusive) |
|||
|
[Recommended Actions] Please update to the following versions: SMA 1000 Series products version 12.4.3-03453 or later, and SMA 1000 Series products version 12.5.0-02835 or later |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





