🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

SonicWall SMA1000 SSRF (CVE-2026-15409) — Actively Exploited, CISA KEV

Critical🔴 KEV ALERTConfirmed
DateJuly 14, 2026
CVECVE-2026-15409
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-15409, a server-side request forgery flaw in SonicWall SMA1000 appliances, to the Known Exploited Vulnerabilities catalog, meaning active exploitation is already underway in the wild. An unauthenticated remote attacker can force the appliance to make requests to arbitrary internal locations, which turns a perimeter device into a pivot point into protected networks. The July 17 patch deadline is a compliance floor, not a safe timeline to wait for.
⚠️Why It Matters for MSSPs
SonicWall SMA1000 appliances are remote access infrastructure, and if your MSSP or any of your clients runs one, an unauthenticated attacker can begin probing internal network segments without a single credential. Your own RMM and PSA back-end systems sit behind exactly this kind of perimeter device, so a successful SSRF against your stack is not a client problem, it is a breach of your entire managed portfolio. If a client gets hit through an unpatched appliance and you had not flagged this advisory, that is a retention conversation you will lose.
Recommended Action
In the next 24 hours, pull your asset inventory and your client asset inventories and identify every SonicWall SMA1000 appliance that is internet-facing. Apply the vendor patch immediately and do not wait for a scheduled maintenance window, because the attacker is not waiting either. Send a direct client notification today, even a short one, so the advisory obligation is documented and your clients know you are watching.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.