Server-side request forgery in SonicWall SMA1000 — remote-access appliances carry markedly higher ransomware association
SonicWall SMA1000 appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to cause the appliance to make requests to unintended locations. It was added to the CISA Known Exploited Vulnerabilities catalog on 2026-07-14 with a due date three days later, and use in ransomware campaigns is known.
Key facts
- CVE IDCVE-2026-15409
- Affected (vendor / product)SonicWall SMA1000 Appliances
- CWECWE-918
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-07-17 (U.S. federal civilian agencies, BOD 22-01)
Key points
- SonicWall SMA1000 appliances contain a server-side request forgery (CWE-918) exploitable without authentication.
- Added to KEV on 2026-07-14 with a due date of 2026-07-17, a three-day grace period. Use in ransomware campaigns is known.
- Among the 1,687 records this site holds as of 2026-09-02, vendors with at least 8 records show ransomware shares of QNAP 81.8% (9/11), SonicWall 76.5% (13/17), Atlassian 61.5% (8/13), Fortinet 48.3% (14/29).
- Overall at that date, 352 of the 1,687 records (20.9%) are marked as known ransomware use.
- The high-share vendors share a common trait: perimeter products such as network storage, remote access and firewalls.
1Making the device issue the request
Server-side request forgery works by feeding crafted input to a device from outside so that the device itself issues a request to some other destination. What makes it awkward is that the sender becomes the device. Internal resources unreachable from outside can be within reach once the request originates inside. Here, a remote unauthenticated attacker could cause the SMA1000 appliance to make requests to unintended locations.
2How often the vendor appears alongside ransomware
Taking the 1,687 KEV records this site holds as of 2026-09-02 and computing, for each vendor with at least 8 records, the share marked as known to be used in ransomware campaigns, the figures above emerge. QNAP is 9 of 11; SonicWall is 13 of 17. Overall, 352 of the 1,687 records (20.9%) are marked as known ransomware use, so these vendors sit well above the average.
3Why the share runs high
The vendors with high shares have something in common: their main products sit on the perimeter of an organization and are reachable from outside — network storage, remote access, firewalls, collaboration platforms. Ransomware operations need an initial foothold from the outside. A known vulnerability left on a perimeter device is the cheapest available entrance.
It reads closer to reality to attribute the elevated share to where the product sits rather than to product quality alone.
4A three-day grace period
The due date is three days after the addition. Across the 1,687 records this site holds as of 2026-09-02 the median grace period is 21 days, so this is considerably shorter than typical. The required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use. Verify applicability with official vendor information and your own environment.
Why it matters
Initial ransomware access frequently runs through a known vulnerability on the perimeter. Enumerating the internet-facing devices in an organization and cross-checking them against KEV listings is a high-return control for the effort involved.
FAQ
Why is SSRF dangerous?
Does a high ransomware share mean poor product quality?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).