CVE-2026-15410
Exploited in the wild. In CISA KEV since 2026‑07‑14. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Confirm whether you use the SMA1000 Appliance Management Console (AMC) and whether any administrator accounts exist for it.
- Assume risk if an attacker can reach the AMC web console and obtain administrator access (even briefly).
- Check with your SonicWall support/Vendor advisory for the specific mitigation details for CVE-2026-15410, since no patch version is currently listed.
- Reduce exposure immediately by restricting network access to the AMC web console (allow only trusted admin IPs/VPN) and block public/internet reachability.
- Follow CISA guidance to prioritize risk-based security updates for this asset and meet the CISA remediation deadline of 2026-07-17.
What it is
From the CVE record
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
In plain language
Written by AI from the recordCVE-2026-15410 is a bug in the SMA1000 Appliance Management Console that lets a logged-in administrator run operating-system commands; because it’s already being used in real attacks, most small businesses should act now if they use this console.
CVE-2026-15410 is a post-authentication code injection in the SMA1000 Appliance Management Console (AMC) that allows a remote authenticated administrator to execute arbitrary OS commands via the web console interface; it’s listed in CISA KEV and exploitation has been confirmed in the wild.
If you're affected
- Full device compromise
- Service disruption
- Admin account takeover
- Malicious changes and persistence
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-07-14.
US federal agencies must remediate by 2026-07-17.
Known use in ransomware campaigns.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
12% chance of exploitation activity in the next 30 days, which ranks it in the 96th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
21 events over 56 days, from the signal feeds we watch.
- Analysis publishedSonicWall's SMA1000 Just Had Its Third Zero-Day SSRF Pair in Nine Months
- EPSS band changehigh → moderateepss band change
- EPSS band changelow → high
- Analysis publishedSonicWall SMA1000: the CVSS 10 "SSRF" that ends in root (CVE-2026-15409)
- EPSS band changemoderate → highepss band change
- Analysis publishedSonicWall SMA1000: the CVSS 10 "SSRF" that ends in root (CVE-2026-15409)
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Scored 7.2 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required HighRequires admin or elevated privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
In the news
All news- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- SonicWall SMA 1000 appliances under attack via zero-day flaws
- SonicWall warns of actively exploited SMA1000 zero-day flaws
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
- Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
- New InfraTrust report reveals infrastructure flaws admins should patch first
- SonicWall SMA zero-days were exploited weeks before disclosure
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for SMA1000, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI