CVE-2026-15409
KEV RANSOMWARECRITICAL 10.0EPSS 83.7%
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 83.66% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-07-14, used in ransomware campaigns
- Nuclei
- critical · CWE-918
- Published
- 2026-07-14
- Updated
- 2026-08-04
Proof-of-concept exploits (6)
- remmons-r7/rapid7-CVE-2026-1540927★ · 2026-07-15
- 0xBlackash/CVE-2026-154093★ · 2026-07-15
- HORKimhab/CVE-2026-154090★ · 2026-07-15
- Ch4120N/CVE-2026-154093★ · 2026-08-03
- tc4dy/CVE-2026-15409-15410-Framework
- tc4dy/CVE-2026-6875-PoC-Exploit