>> All posts

CVE-2026-15410: SonicWall SMA1000 command injection, actively exploited

The short version: SonicWall's SMA1000 secure-access appliances have a command-injection flaw (CVE-2026-15410) that attackers are already using in the wild — chained with a second bug to take over the box. It's in CISA's Known Exploited Vulnerabilities catalog with a July 17 remediation deadline. If you run these appliances, this is a this-week job. Steady hands, but move.

At a glance

FactDetail
Our severity takeCritical in practice (see below)
CVSS v3.1 (NVD)7.2 — High · AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS (SonicWall, chained)10.0 — Critical
EPSS1.65% · 74th percentile (2026-07-15)
In CISA KEV?Yes — remediate by 2026-07-17 (BOD 26-04)
Known exploited?Yes — actively exploited, chained with CVE-2026-15409
Vulnerability typeCWE-94 code injection → arbitrary OS command execution
Requires authenticated session?Yes — post-auth, admin (PR:H); the companion bug supplies access in observed attacks
AffectedSMA1000 series: SMA6210, SMA7210, SMA8200v (12.4.3-03245 → 12.5.0-02800)
Fixed in12.4.3-03453 or 12.5.0-02835

What you need to know

CVE-2026-15410 is a post-authentication code-injection vulnerability in the SMA1000 Appliance Management Console. An authenticated administrator can inject and run arbitrary operating-system commands — full control of the appliance.

On its own, that "authenticated administrator" requirement is a real barrier, which is why NVD scores it 7.2 (High). The problem is that it isn't being used on its own. In the attacks observed so far, CVE-2026-15410 is chained with a companion vulnerability, CVE-2026-15409, so an attacker who starts with no access ends with code execution on a device that sits at the edge of your network and brokers remote access into it. That's why SonicWall's advisory rates the combined situation a 10.0.

Two details make this one worth prioritizing over a typical "High":

  • It's an access appliance. Compromising the SMA1000 doesn't just breach one host — it can hand an attacker the keys to remote access itself.
  • It's already happening. SonicWall confirmed active exploitation and CISA added it to KEV, which means the theoretical is now operational.

How serious we see it

Critical — in practice, not on paper.

We don't say that lightly, and it isn't about the 7.2 base score. It's the combination: an internet-facing security appliance, a working exploit chain that reaches full code execution, and confirmed exploitation in the wild. When those line up on a device that guards remote access, the calm, correct response is to treat it as top of the queue.

The reassuring part is that this one is bounded and fixable. It affects a specific product line and specific versions, the fix exists, and you can tell quickly whether it applies to you.

Recommendations

Straight from SonicWall's and CISA's guidance:

  1. Patch now. Upgrade affected SMA1000 appliances (SMA6210, SMA7210, SMA8200v) to 12.4.3-03453 or 12.5.0-02835. Federal agencies have until July 17, 2026 under BOD 26-04; treat that as everyone's deadline.
  2. Assume nothing — hunt. SonicWall is explicit that patching alone is not sufficient. Review appliance logs for indicators of compromise, following their KB guidance closely.
  3. If you find IoCs, rebuild. Re-image (hardware) or re-deploy (virtual) the appliance, and rotate all user and administrator passwords and reset TOTP tokens.
  4. Harden the console. Restrict access to the Appliance Management Console, enforce MFA on admin accounts, and limit who can reach it from the internet — the auth requirement works in your favor only if you keep it strong.
  5. Confirm your exposure first. Before anything else, verify whether you have an internet-facing SMA1000 at all, and which firmware it runs.

How BreachRisk sees it

That last step — do we even have one of these exposed? — is exactly what BreachRisk answers. From little more than your website, it discovers your internet-facing appliances, fingerprints the SMA1000 management console and its firmware version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one. We already surface it — and because it's in KEV, it rises straight to the top of the priority list instead of getting lost in a scanner's backlog.

The whole point of a continuous, attacker's-eye view is that a brand-new KEV entry doesn't send you hunting — the exposure is already on your radar.

References

See your cyber risk, proven.