Product of SonicWall

SMA1000 Appliances

As of , 5 SonicWall SMA1000 Appliances vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-83548.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-83548Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.09
2CVE-2026-83549OS Command InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.11
3CVE-2026-15409Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.07
4CVE-2026-15410Code InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year0.12
5CVE-2025-23006DeserializationSonicWall SMA1000 AppliancesPatch this weekRansomware use0.23

Added each year

12342025: 1120252026: 442026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20251
20264

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-15410 SonicWall SMA1000 AppliancesRansomware use: Unknown to Known.
  2. CVE-2026-15409 SonicWall SMA1000 AppliancesRansomware use: Unknown to Known.
  3. CVE-2025-23006 SonicWall SMA1000 AppliancesRansomware use: Unknown to Known.

Every change we recorded