← Vulnerability feed

Vulnerability record · CVE-2026-15410 · published 14 July 2026

CVE-2026-15410: SonicWall SMA1000 AMC code injection allows OS command execution

Sonicwall · Sma6210 Firmware

The SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an authenticated administrator execute arbitrary OS commands. It affects SMA6210, SMA7210 and SMA8200v firmware. Because it yields OS-level command execution on a security appliance, it is a serious post-compromise escalation and persistence vector.

7.2 CVSS 3.1 High CISA KEV since 14 Jul 2026 Known ransomware use EPSS 12% · top 4.1% CWE-94 · Code injection
7.2CVSS 3.1 base score
12%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
16 Jul 2026Last modified by NVD

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, a three-day remediation deadline and a high-severity CVSS of 7.2, despite requiring administrator authentication.

What it is

The SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an authenticated administrator execute arbitrary OS commands. It affects SMA6210, SMA7210 and SMA8200v firmware. Because it yields OS-level command execution on a security appliance, it is a serious post-compromise escalation and persistence vector.

Impact

An attacker who already holds administrator credentials gains arbitrary OS command execution on the appliance, enabling full control of the device, data access and further lateral movement.

Attack surface

Reachable over the network via the AMC interface (AV:N, AC:L, UI:N), but it requires high privileges, meaning valid administrator authentication is needed before the flaw can be triggered.

Exploitation

CVE-2026-15410 was added to CISA KEV on 2026-07-14 with a remediation due date of 2026-07-17 and is flagged for known ransomware campaign use; EPSS gives a 30-day probability of 0.11791 (95.86th percentile). No public exploit references are listed beyond the vendor advisory and the KEV entry.

What to do

  • Apply the SonicWall vendor fix per advisory SNWLID-2026-0008 as the first action.
  • Follow CISA BOD 26-04 guidance, including the KEV required action and forensics triage requirements.
  • Restrict AMC administrative access to trusted management networks and remove internet exposure where possible.
  • Rotate administrator credentials and review admin accounts for unauthorized changes.
  • If mitigations are unavailable, discontinue use of the affected appliance as CISA advises.

Detection

  • Hunt AMC and appliance logs for unexpected OS command execution or child processes spawned by the management console.
  • Monitor for anomalous administrator logins and post-login activity on SMA1000 appliances.
  • Alert on new or modified files, scheduled tasks or services on the appliance consistent with persistence.
  • Review network flows to and from the AMC interface for unusual outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-15410 to the Known Exploited Vulnerabilities catalog on 14 July 2026 as "SonicWall SMA1000 Appliances Code Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 17 July 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-15410 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed9.8CVE-2025-23006SonicWall SMA1000 pre-auth deserialization allows OS command executionThe SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific condition…KEVEPSS 23%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed6.6CVE-2025-40602SonicWall SMA1000 management console missing authorization privilege escalationThe SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to C…KEVEPSS 2.8%analysed7.2CVE-2026-4116Sonicwall sma6210 firmware vulnerabilityImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu…EPSS 0.71%7.2CVE-2026-4112Sonicwall sma6210 firmware sql injection vulnerabilityImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic…EPSS 0.53%7.2CVE-2026-4113Sonicwall sma6210 firmware vulnerabilityAn observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2026-15410), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.