CVE-2026-15409
CRITICAL
CVSS: 10.0
EPSS: 84.5%
VulnCheck KEV
Weaponized
Metasploit
CWE-918
T1190
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Published: 2026-07-14