High severity7.2CISA KEVNVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-15410
CVE-2026-15410
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Affected products
19cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:sma8200v:12.4.3-03387:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:sma8200v:12.4.3-03434:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:sma8200v:12.5.0-02283:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:sma8200v:12.5.0-02624:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:sma8200v:12.5.0-02800:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03387:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03434:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02283:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02624:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02800:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03245:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03387:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03434:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02283:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02624:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02800:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
10- CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy RansomwareCyber Security News · Aug 11, 2026
- Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 StoriesCyber Security News · Aug 9, 2026
- Prolific ransomware group behind SonicWall zero-day attacksCyberScoop · Aug 4, 2026
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsThe Hacker News · Aug 3, 2026
- Recent SonicWall Vulnerabilities Exploited in Ransomware AttacksSecurityWeek · Aug 3, 2026
- Internet-Facing SonicWall SMA Appliances Face Zero-Click Root CompromiseCyber Security News · Aug 3, 2026
- Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breachedHelp Net Security · Jul 26, 2026
- July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall FlawsCyber Security News · Jul 23, 2026
- New InfraTrust report reveals infrastructure flaws admins should patch firstBleepingComputer · Jul 22, 2026
- SonicWall: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Jul 14, 2026