• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-15410: authenticated code injection in SonicWall SMA1000 Appliances

A remote authenticated administrator can execute arbitrary operating-system commands on SonicWall SMA1000 Appliances, impacting devices that run the appliance management console. CVE-2026-15410 is a post-authentication code injection flaw affecting specific 12.x builds; the known affected ranges are 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. An attacker needs valid administrative credentials to exploit this vulnerability over the network.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.2HIGH
EPSS
0.11791
CWE
CWE-94
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added CVE-2026-15410 to its Known Exploited Vulnerabilities catalog with a July 17, 2026 mitigation deadline, so prioritize remediation for internet-exposed SMA1000 Appliances immediately.

What is CVE-2026-15410?

A remote authenticated administrator can execute arbitrary operating-system commands on SonicWall SMA1000 Appliances, impacting devices that run the appliance management console. CVE-2026-15410 is a post-authentication code injection flaw affecting specific 12.x builds; the known affected ranges are 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. An attacker needs valid administrative credentials to exploit this vulnerability over the network.

Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Which versions of SonicWall SMA1000 Appliances are affected?

BRANCHAFFECTEDFIXED
12.x12.4.3-03245 – 12.4.3-03434
12.x12.5.0-02283 – 12.5.0-02800

Is CVE-2026-15410 being exploited?

CISA added CVE-2026-15410 to the Known Exploited Vulnerabilities catalog on 2026-07-14; U.S. federal agencies must address it by 2026-07-17. Public exploit code is also available.

How to fix CVE-2026-15410

  1. Follow SonicWall vendor guidance and apply any provided mitigations immediately.
  2. Restrict network exposure of SMA1000 management interfaces to trusted hosts and VPNs.
  3. Monitor appliance logs and network traffic for indicators of compromise and unauthorized administrative activity.
  4. If mitigations are not available or adequate, consider discontinuing use or isolating affected appliances per CISA guidance.

Frequently asked questions

Is CVE-2026-15410 being actively exploited?

Yes; CISA added CVE-2026-15410 to its Known Exploited Vulnerabilities catalog on 2026-07-14 and lists known ransomware campaign use, with a remediation deadline of 2026-07-17 for U.S. federal agencies.

Which SMA1000 Appliances versions are affected by CVE-2026-15410?

The vulnerability affects SMA1000 Appliance builds in the ranges 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800.

Is there a patch for CVE-2026-15410?

No patch is listed in the available facts; patchAvailable is false, so follow SonicWall mitigations and exposure restrictions until a fix is published.

Does CVE-2026-15410 require authentication?

Yes; this is a post-authentication code injection in the SMA1000 Appliance management console and requires valid administrative credentials to exploit.

References