{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-15409",
  "revision": 1,
  "title": "SonicWall SMA1000 — unauthenticated request forgery in Work Place",
  "summary": "SonicWall Secure Mobile Access 1000 (SMA1000) appliances let an unauthenticated visitor to the Work Place portal make the appliance issue requests of the attacker's choosing, reaching internal systems the appliance can see but the attacker cannot.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.84535,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-07-14",
    "prerequisites": "Network access to the appliance's Work Place interface; no credentials needed."
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Patch SMA1000 per SonicWall SNWLID-2026-0008 now; it is used in ransomware activity, so treat exposed appliances as compromised until proven otherwise.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-15409",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008"
    }
  ],
  "published_at": "2026-07-14T20:16:56.783Z",
  "issued_at": "2026-09-23T07:33:20.707Z",
  "tags": [
    "sonicwall",
    "sma1000",
    "ssrf",
    "vpn",
    "ransomware",
    "kev"
  ]
}
