All CVEs
Vulnerability intelligence

CVE-2026-15410

CWE-94

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CVSS Score
7.2
High
EPSS — Exploit Probability
12%
Riskier than 96% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-17
NVD entry Vendor patch PoC / advisory CISA KEV

14 articles across 8 outlets · first covered Jul 14, 2026 · latest Aug 4, 2026

Associated threat actors

Coverage timeline