LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 14, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 17, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-15410 to its Known Exploited Vulnerabilities catalog on Jul 14, 2026, with a federal patch deadline of Jul 17, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS…

SonicWall SMA1000 Appliances contain a code injection vulnerability identified as CVE-2026-15410. In specific conditions, the flaw could allow a remote authenticated attacker with administrator privileges to execute arbitrary operating system commands. The issue is relevant to organizations that rely on these appliances for secure remote access, as successful exploitation may provide an attacker with direct control over the affected device and any connected resources.

How it works

CWE-94 covers weaknesses in which software does not properly neutralize or constrain code that is generated or executed at runtime. The vulnerability in SonicWall SMA1000 Appliances falls into this class.

An attacker who already possesses valid administrator credentials may be able to supply crafted input that results in the execution of operating system commands when particular conditions are present. Exact prerequisites, affected code paths, and input vectors are not detailed in the available summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

SonicWall SMA1000 Appliances are typically deployed as on-premises or data-center security gateways that provide VPN and remote-access services. Begin by locating every instance of these appliances through asset inventories, network discovery scans, and configuration management databases.

How to remediate

Apply the vendor-supplied update referenced in the official SonicWall advisory. This is the primary and most effective remediation.

If you can't patch immediately

Until the update can be deployed, place the management interface behind network segmentation controls that limit inbound connections to trusted sources only. Disable or tightly restrict any non-essential administrative services on the appliance.

Continue to monitor CISA BOD 26-04 guidance for any additional requirements that apply to internet-exposed assets.

If your data may have been exposed

Code injection vulnerabilities that permit operating system command execution have been used to facilitate unauthorized access. Organizations can run a free exposure scan of their email addresses against known breach data to determine whether related credentials appear in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SMA1000 Appliances
WeaknessCWE-94
Added to CISA KEVJul 14, 2026
Federal patch deadlineJul 17, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities