CISA KEV · catalog date Jul 14, 2026 · first observed Aug 3, 2026
Evidence dossier
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
Exploited in the wild (CISA KEV since Jul 14, 2026). CISA-ADP reports CVSS 3.1 10.0. EPSS estimates 83.7% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- State
- PUBLISHED
- Published
- Jul 14, 2026
- Updated
- Aug 4, 2026
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAsonicwallOriginal evidence ↗
Record text: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Inspect raw assertion
- Field
container- Value
- A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 83.66% probability · 99.67th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.836580000000; percentile 0.996670000000
FIRST EPSS · score date Aug 27, 2026 · 99.7th percentile · first observed Aug 27, 2026
CISA-ADP · CVSS 3.1 · first observed Aug 4, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Inspect raw assertion
- Field
container- Value
- A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
83.66% probability · 99.67th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.836580000000; percentile 0.996670000000
Applicability
Cited product scope
Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
7 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "12.4.3-03245", "versionType": "custom", "lessThanOrEqual": "12.4.3-03434"}, {"status": "affected", "version": "12.5.0-02283", "versionType": "custom", "lessThanOrEqual": "12.5.0-02800"}]product-3fe341af8382fae157bb26d88c651ef91f414f88dcdd4994e4f6a7388805bad1Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7b24d300-1154-49a1-a1f3-fb0cc717166a
product-6f624227d2e5ec64ceb81a982767d5722fdcd2dc1c8f888475df73750113b8b0Linked exactInspect raw assertions
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03387:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e4a6ca48-e2d9-4f18-8fc8-b1ee7f51789c
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02283:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ce23bd37-4112-407f-9e34-04cb5a4da996
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03434:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ebce7761-8416-4942-b0bd-426efc73b57c
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f861049-5b88-4e18-a0e7-d1e2bc7a4342
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02800:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
75f6b9ce-73e4-42be-9ce1-fd79255cdd0b
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02624:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
95e3313e-0647-40ed-9848-5ac01188a84f
product-bc6f664572e6d3c25216e10a8ec9cdd628a19ca537e6a40c62916991348ba356Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e9b414c5-c376-4216-a267-abc0930905ce
product-159026eb0d2db11b30f641a0b5a2363858106a2bd374a9c447f8147a6e992de0Linked exactInspect raw assertions
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03387:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eaf12d10-fa8f-471e-b008-68e0e29089c6
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03245:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
55cd7766-9f2d-450d-a878-aa1522e8ff68
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03434:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79920402-165d-4d81-bfd2-9f679a48671a
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02624:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6af4557f-abaf-4795-915a-695383f64eeb
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02283:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6842e4d7-beda-41fb-aec3-ceb3692374c2
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02800:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9459507a-a2c8-400d-8669-e8adbde61de0
product-bfcdaca7fb346b90df5d5a2cff392214a1dfa19a92c55c4930aef860bd8b62b7Linked exactInspect raw assertions
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02283:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2f44543-2404-4cdf-9d2f-1b851660f5d5
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02624:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1e14f40f-4aa1-42b4-998e-ac965fbbe519
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
571c9ca1-f660-4479-9e91-b3b1714a2090
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03434:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9e698dfa-1684-43e3-9964-0e207a7a2cc1
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02800:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
43197e99-0500-4971-8a66-4e70f8138289
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03387:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58706c99-b77f-4ae5-bd45-eba65dee2485
product-bfcdaca7fb346b90df5d5a2cff392214a1dfa19a92c55c4930aef860bd8b62b7Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
653b5f4d-7417-4a85-b385-46157a1540a6
Affected-product evidence
Accepted scope and product mapping
3 canonical links · 1 source-reported links
vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-159026eb0d2db11b30f641a0b5a2363858106a2bd374a9c447f8147a6e992de0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2590de9c-e5cb-4197-a4c4-0a01af3a108c4c73fb01-0ab8-400b-b73e-17580966a3ce78dead30-88fb-4f00-a591-91dd0c14cfedd2d25553-b260-4a9a-a9f5-3dc8dbc4f380dbdf1df5-32d0-4066-a6ca-3916af01de63fb363981-3525-45d3-8b3a-832994c1951dvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-6f624227d2e5ec64ceb81a982767d5722fdcd2dc1c8f888475df73750113b8b0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
106b1c8e-3241-494e-95cd-21982f97ed111714d3e0-04c7-4b9a-b496-efa7e1510a9320c3ab39-7558-4d4f-9df0-640ab3ea7e4a846d6332-5fac-4309-be45-d23a4b0a6f9ca8e82675-0de6-4c60-b657-48250fd95956edad9cd3-9e30-4bba-ae83-eb1ee71fab55vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-bfcdaca7fb346b90df5d5a2cff392214a1dfa19a92c55c4930aef860bd8b62b7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3973729a-47c8-447f-85f1-0ea36976cd793be92fc8-d076-4ed2-ad43-5bc81d388f924b24a491-6243-4e3d-9190-389e9748a72780cc119d-4cd4-42cf-bdf0-28f580d2fe05b94aac70-653b-4c46-9ccc-74b86bcd6679e1fdde59-cb43-4bdb-8653-2c221021cb2bCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b8ef6387-7699-4d73-89fe-def1bdb7c68bAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 10.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.