Vulnerability intelligence
CVE-2026-15410
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVSS Score
7.2
High
EPSS — Exploit Probability
12%
Riskier than 96% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-17
14 articles across 8 outlets · first covered Jul 14, 2026 · latest Aug 4, 2026
Associated threat actors
Coverage timeline
-
INC Ransomware abuses CVE-2026-15409 in SonicWall, calls victimssecurityaffairs.com · Aug 4, 2026
-
INC Ransomware exploits CVE-2026-15409, gains root on SonicWallwww.securityweek.com · Aug 3, 2026
-
SonicWall SMA Exploit Chain Now Fuels INC Ransomware Attackssecurityonline.info · Aug 3, 2026
-
SonicWall SMA 1000 zero day used to spread KNUCKLEBALLsocradar.io · Jul 21, 2026
-
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patchwww.securityweek.com · Jul 20, 2026
-
Zero day exploits hit SonicWall VPN, giving attackers root accesssecurityaffairs.com · Jul 20, 2026
-
Zero day exploit targets SonicWall SMA 1000, installs malwaresecurityonline.info · Jul 19, 2026
-
SonicWall CVE-2026-15409 flaw lets ransomware group hijack VPNswww.darkreading.com · Jul 17, 2026
-
Microsoft, SonicWall bugs found; RabbitMQ patches auth flawssecurityonline.info · Jul 15, 2026
-
SonicWall SMA1000 flaws exploited, urgent patch advisedwww.rapid7.com · Jul 15, 2026
-
CISA Flags SonicWall SMA1000 and Microsoft Flaws in KEV Catalogsecurityaffairs.com · Jul 15, 2026
-
SonicWall Warns of Active Exploitation of SMA 1000 Zero Dayssecurityaffairs.com · Jul 15, 2026
-
CISA Adds SonicWall SMA1000 Code Injection Flaw to KEV Catalogwww.cisa.gov · Jul 14, 2026
-
CISA Flags CVE‑2026-15410 in KEV After SonicWall SMA1000 Exploitcisa.gov · Jul 14, 2026