Critical SSRF and UAF Vulnerabilities Discovered in SonicWall and Linux Kernel

Critical SSRF and UAF Vulnerabilities Discovered in SonicWall and Linux Kernel

First seen 7 Sep 2026, 09:23 UTC Sploitus 72.8

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been reported on September 7, 2026. CVE-2026-15409 is a critical Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 series devices, allowing remote attackers to execute unintended HTTP requests. This vulnerability has been actively exploited since its disclosure on July 14, 2026. CVE-2026-23111 is a high-severity Use-After-Free (UAF) vulnerability in the Linux kernel's netfilter/nf_tables, potentially allowing local attackers to escalate privileges. The UAF vulnerability was published on February 13, 2026, with a proof-of-concept released on June 9, 2026. Both vulnerabilities pose significant risks to affected systems and require immediate attention from security professionals.

Key Points: • CVE-2026-15409 allows remote exploitation on SonicWall SMA1000 devices. • CVE-2026-23111 presents a local privilege escalation risk in the Linux kernel. • Both vulnerabilities are critical and require immediate remediation efforts.

Ask AI about this cluster

Timeline

2026-02-13
CVE-2026-23111 published
High-severity UAF vulnerability in Linux kernel's netfilter/nf_tables disclosed.
Sploitus
2026-06-09
First public PoC for CVE-2026-23111
Proof-of-concept code for the UAF vulnerability was released to the public.
Sploitus
2026-07-14
CVE-2026-15409 published
Critical SSRF vulnerability in SonicWall SMA1000 series devices disclosed, allowing remote exploitation.
Sploitus
2026-07-14
CVE-2026-15409 added to CISA KEV
CISA confirmed active exploitation of CVE-2026-15409 in the wild.
Sploitus
2026-07-15
First public PoC for CVE-2026-15409
Proof-of-concept code for the SSRF vulnerability was made publicly available.
Sploitus
2026-09-07
Current status of vulnerabilities
Both CVE-2026-15409 and CVE-2026-23111 are critical and high-severity vulnerabilities that require immediate remediation.
Sploitus