peter bassill · operator
$ cve CVE-2026-15410 JSON

CVE-2026-15410 KEV

7.2
HIGH · CVSS 3.1 · EPSS 11.8% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-17.

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS11.79% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2026-07-17
Public exploitnone known
Published2026-07-14
Last modified2026-07-16

CISA KEV

NameSonicWall SMA1000 Appliances Code Injection Vulnerability
Added2026-07-14
Due2026-07-17
Vendor / productSonicWall / SMA1000 Appliances
Ransomware useknown

Affected (5)

VendorProduct
sonicwallsma6210
sonicwallsma6210 firmware
sonicwallsma7210
sonicwallsma7210 firmware
sonicwallsma8200v

References

→ the Explorer  ·  watch your stack  ·  NVD