Exploited Known exploited (KEV) Ransomware use CVE-2026-15409

Server-side request forgery in SonicWall SMA1000 — remote-access appliances carry markedly higher ransomware association

SonicWall SMA1000 Appliances Added to KEV Jul 14, 2026 Federal remediation due 2026-07-17

SonicWall SMA1000 appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to cause the appliance to make requests to unintended locations. It was added to the CISA Known Exploited Vulnerabilities catalog on 2026-07-14 with a due date three days later, and use in ransomware campaigns is known.

Key facts

  • CVE IDCVE-2026-15409
  • Affected (vendor / product)SonicWall SMA1000 Appliances
  • CWECWE-918
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-07-17 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • SonicWall SMA1000 appliances contain a server-side request forgery (CWE-918) exploitable without authentication.
  • Added to KEV on 2026-07-14 with a due date of 2026-07-17, a three-day grace period. Use in ransomware campaigns is known.
  • Among the 1,687 records this site holds as of 2026-09-02, vendors with at least 8 records show ransomware shares of QNAP 81.8% (9/11), SonicWall 76.5% (13/17), Atlassian 61.5% (8/13), Fortinet 48.3% (14/29).
  • Overall at that date, 352 of the 1,687 records (20.9%) are marked as known ransomware use.
  • The high-share vendors share a common trait: perimeter products such as network storage, remote access and firewalls.

1Making the device issue the request

Server-side request forgery works by feeding crafted input to a device from outside so that the device itself issues a request to some other destination. What makes it awkward is that the sender becomes the device. Internal resources unreachable from outside can be within reach once the request originates inside. Here, a remote unauthenticated attacker could cause the SMA1000 appliance to make requests to unintended locations.

2How often the vendor appears alongside ransomware

QNAP81.8 / 100
SonicWall76.5 / 100
Atlassian61.5 / 100
Fortinet48.3 / 100
Palo Alto Networks40.0 / 100
VMware34.6 / 100

Taking the 1,687 KEV records this site holds as of 2026-09-02 and computing, for each vendor with at least 8 records, the share marked as known to be used in ransomware campaigns, the figures above emerge. QNAP is 9 of 11; SonicWall is 13 of 17. Overall, 352 of the 1,687 records (20.9%) are marked as known ransomware use, so these vendors sit well above the average.

3Why the share runs high

The vendors with high shares have something in common: their main products sit on the perimeter of an organization and are reachable from outside — network storage, remote access, firewalls, collaboration platforms. Ransomware operations need an initial foothold from the outside. A known vulnerability left on a perimeter device is the cheapest available entrance.

It reads closer to reality to attribute the elevated share to where the product sits rather than to product quality alone.

4A three-day grace period

The due date is three days after the addition. Across the 1,687 records this site holds as of 2026-09-02 the median grace period is 21 days, so this is considerably shorter than typical. The required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use. Verify applicability with official vendor information and your own environment.

Why it matters

Initial ransomware access frequently runs through a known vulnerability on the perimeter. Enumerating the internet-facing devices in an organization and cross-checking them against KEV listings is a high-return control for the effort involved.

FAQ

Why is SSRF dangerous?
Because the request originates from the device itself, internal resources unreachable from outside can be within reach by routing through it.
Does a high ransomware share mean poor product quality?
The records support only the difference in shares. The high-share vendors lead with perimeter products, so it reads closer to reality to attribute the pattern to where the product sits.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#SonicWall#Ransomware#SSRF
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.