August 30, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-15409NVD

Vulnerability Summary

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Severity Level
CRITICAL(10.0)
Published Date
Jul 14, 2026
Last Modified
Jul 16, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
74.22%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh