CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Other sources
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15410?
CVE-2026-15410 has a high severity rating of 7.2 on the CVSS scale.
How do I fix CVE-2026-15410?
To fix CVE-2026-15410, update the SonicWall SMA1000 Appliances firmware to the latest version as soon as possible.
What types of devices are affected by CVE-2026-15410?
CVE-2026-15410 affects SonicWall SMA6210, SMA7210, SMA8200v appliances, and the SMA1000 Appliance Management Console.
What is the primary risk associated with CVE-2026-15410?
The primary risk of CVE-2026-15410 is that a remote authenticated attacker could execute arbitrary OS commands on the affected systems.
Is CVE-2026-15410 actively exploited?
Yes, CVE-2026-15410 is listed as an actively exploited vulnerability.