Vulnerability record · CVE-2026-15410 · published 14 July 2026
CVE-2026-15410: SonicWall SMA1000 AMC code injection allows OS command execution
Sonicwall · Sma6210 Firmware
The SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an authenticated administrator execute arbitrary OS commands. It affects SMA6210, SMA7210 and SMA8200v firmware. Because it yields OS-level command execution on a security appliance, it is a serious post-compromise escalation and persistence vector.
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, a three-day remediation deadline and a high-severity CVSS of 7.2, despite requiring administrator authentication.
What it is
The SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an authenticated administrator execute arbitrary OS commands. It affects SMA6210, SMA7210 and SMA8200v firmware. Because it yields OS-level command execution on a security appliance, it is a serious post-compromise escalation and persistence vector.
Impact
An attacker who already holds administrator credentials gains arbitrary OS command execution on the appliance, enabling full control of the device, data access and further lateral movement.
Attack surface
Reachable over the network via the AMC interface (AV:N, AC:L, UI:N), but it requires high privileges, meaning valid administrator authentication is needed before the flaw can be triggered.
Exploitation
CVE-2026-15410 was added to CISA KEV on 2026-07-14 with a remediation due date of 2026-07-17 and is flagged for known ransomware campaign use; EPSS gives a 30-day probability of 0.11791 (95.86th percentile). No public exploit references are listed beyond the vendor advisory and the KEV entry.
What to do
- Apply the SonicWall vendor fix per advisory SNWLID-2026-0008 as the first action.
- Follow CISA BOD 26-04 guidance, including the KEV required action and forensics triage requirements.
- Restrict AMC administrative access to trusted management networks and remove internet exposure where possible.
- Rotate administrator credentials and review admin accounts for unauthorized changes.
- If mitigations are unavailable, discontinue use of the affected appliance as CISA advises.
Detection
- Hunt AMC and appliance logs for unexpected OS command execution or child processes spawned by the management console.
- Monitor for anomalous administrator logins and post-login activity on SMA1000 appliances.
- Alert on new or modified files, scheduled tasks or services on the appliance consistent with persistence.
- Review network flows to and from the AMC interface for unusual outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-15410 to the Known Exploited Vulnerabilities catalog on 14 July 2026 as "SonicWall SMA1000 Appliances Code Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 17 July 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410 | US Government Resource |
Track CVE-2026-15410 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-15410), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.