DIRAS TAKE
Urgent: CISA added CVE-2026-15410 to its Known Exploited Vulnerabilities catalog with a July 17, 2026 mitigation deadline, so prioritize remediation for internet-exposed SMA1000 Appliances immediately.
What is CVE-2026-15410?
A remote authenticated administrator can execute arbitrary operating-system commands on SonicWall SMA1000 Appliances, impacting devices that run the appliance management console. CVE-2026-15410 is a post-authentication code injection flaw affecting specific 12.x builds; the known affected ranges are 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. An attacker needs valid administrative credentials to exploit this vulnerability over the network.
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Which versions of SonicWall SMA1000 Appliances are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 12.x | 12.4.3-03245 – 12.4.3-03434 | |
| 12.x | 12.5.0-02283 – 12.5.0-02800 |
Is CVE-2026-15410 being exploited?
CISA added CVE-2026-15410 to the Known Exploited Vulnerabilities catalog on 2026-07-14; U.S. federal agencies must address it by 2026-07-17. Public exploit code is also available.
How to fix CVE-2026-15410
- Follow SonicWall vendor guidance and apply any provided mitigations immediately.
- Restrict network exposure of SMA1000 management interfaces to trusted hosts and VPNs.
- Monitor appliance logs and network traffic for indicators of compromise and unauthorized administrative activity.
- If mitigations are not available or adequate, consider discontinuing use or isolating affected appliances per CISA guidance.
Frequently asked questions
Is CVE-2026-15410 being actively exploited?
Yes; CISA added CVE-2026-15410 to its Known Exploited Vulnerabilities catalog on 2026-07-14 and lists known ransomware campaign use, with a remediation deadline of 2026-07-17 for U.S. federal agencies.
Which SMA1000 Appliances versions are affected by CVE-2026-15410?
The vulnerability affects SMA1000 Appliance builds in the ranges 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800.
Is there a patch for CVE-2026-15410?
No patch is listed in the available facts; patchAvailable is false, so follow SonicWall mitigations and exposure restrictions until a fix is published.
Does CVE-2026-15410 require authentication?
Yes; this is a post-authentication code injection in the SMA1000 Appliance management console and requires valid administrative credentials to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15410
- cve.org/CVERecord?id=CVE-2026-15410
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- All SonicWall CVEs on CVE Radar
- CVEs published in September 2026