Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3752 articles · 207518 vulns · 36/41 feeds (7d)
← Back to list
7.2
CVE-2026-15410EXPLOITEDPATCHED
sonicwall · sma6210_firmware

CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Affected Products

VendorProductVersions
sonicwallsma6210_firmware12.4.3-03245, 12.5.0-02283

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallsmacert_advisory90%
sonicwallsma7210_firmwarecve_cpe95%
sonicwallsma8200vcve_cpe95%
sonicwallsma6210cve_cpe95%
sonicwallsma7210cve_cpe95%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008(vendor-advisory)

Related News (25 articles)

Tier D
BleepingComputer3h ago
SonicWall warns of actively exploited SMA1000 zero-day flaws
→ No new info (linked only)
Tier D
BleepingComputer22d ago
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
→ No new info (linked only)
Tier D
The Hacker News29d ago
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
→ No new info (linked only)
Tier C
Rapid7 Blog33d ago
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
→ No new info (linked only)
Tier C
Rapid7 Blog35d ago
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
→ No new info (linked only)
Tier D
Help Net Security38d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier D
BleepingComputer41d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
→ No new info (linked only)
Tier C
Rapid7 Blog41d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
Help Net Security42d ago
SonicWall SMA zero-days were exploited weeks before disclosure
→ No new info (linked only)
Tier D
BleepingComputer43d ago
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
→ No new info (linked only)
Tier D
SecurityWeek43d ago
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
→ No new info (linked only)
Tier D
The Hacker News43d ago
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
→ No new info (linked only)
Tier D
The Hacker News44d ago
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
→ No new info (linked only)
Tier D
Help Net Security45d ago
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
→ No new info (linked only)
Tier E
Hacker News48d ago
CVE-2026-15409: SonicWall SMA 1000 SSRF Zero-Day
→ No new info (linked only)
Tier C
Rapid7 Blog48d ago
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
→ No new info (linked only)
Tier B
BSI Advisories48d ago
[NEU] [kritisch] SonicWall SMA: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security48d ago
SonicWall SMA1000: Angriffe auf teils kritische Zero-Day-Lücken
→ No new info (linked only)
Tier D
SecurityWeek49d ago
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
→ No new info (linked only)
Tier C
VulDB49d ago
CVE-2026-15410 | SonicWall SMA1000 up to 12.4.3-03434/12.5.0-02800 Management Console code injection
→ No new info (linked only)
Tier B
CERT-FR49d ago
Multiples vulnérabilités dans Secure Mobile Access (15 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR49d ago
Multiples vulnérabilités dans Sonicwall Secure Mobile Access 1000 (15 juillet 2026)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity49d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier D
BleepingComputer49d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier B
CCCS Canada49d ago
SonicWall security advisory (AV26-699) – Update 1
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
CWECWE-94
PublishedJul 14, 2026
Last enriched43d agov12
Tags
SonicWallSecure Mobile AccessZero-DayUTA0533Chained with CVE-2026-15409KEV CatalogKnuckleBall malwareOrangeTail webshellSuo5 proxy
Trending Score107🔥
Source articles25
Independent12
Info Completeness11/14
Missing: epss, kev, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-83548EXPKEV
CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
Trending: 119
HIGHCVE-2026-83549EXPKEV
CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Trending: 116
HIGHCVE-2026-66152
CVE-2026-66152: A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to
Trending: 17
HIGHCVE-2026-66153
CVE-2026-66153: The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows
Trending: 17
CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 13

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, cweIds
Jul 14, 2026
Updated: affectedVersions
Jul 14, 2026
Updated: severity, activelyExploited
Jul 15, 2026
Updated: affectedVersions
Jul 15, 2026
Updated: affectedVersions
Jul 15, 2026
Updated: affectedVersions, exploitAvailable, tags
Jul 15, 2026
Updated: affectedVersions, iocs
Jul 15, 2026
Updated: affectedVersions, tags
Jul 15, 2026
Updated: tags
Jul 20, 2026
Updated: tags
Jul 20, 2026
Updated: affectedVersions, description
Jul 20, 2026
Actively Exploited
Aug 4, 2026
Exploit Available
Aug 4, 2026
Patch Available
Aug 4, 2026

Version History

v12
Last enriched 43d ago
v12Tier D43d ago

Added patched versions (12.4.3-03453, 12.5.0-02835) and significantly expanded description with technical exploitation details including the attack chain, RPC method exploited, and malware payload information.

affectedVersionsdescription
via BleepingComputer
v11Tier D43d ago

Added malware artifacts (KnuckleBall, OrangeTail, Suo5) deployed post-exploitation and KEV Catalog tag; confirmed remote unauthenticated attack vector contrary to previous authentication requirement in description.

tags
via SecurityWeek
v10Tier D43d ago

Added threat actor attribution (UTA0533) and confirmation that CVE-2026-15410 was exploited as a zero-day since June 22, 2026, chained with CVE-2026-15409 for command execution.

tags
via The Hacker News
v9Tier C48d ago

Updated description with technical details, added new affected versions, and included new relevant tags.

affectedVersionstags
via Rapid7 Blog
v8Tier B48d ago

Updated affected versions to include 12.5.x prior to 12.5.0-02835 and 12.4.3 prior to 12.4.3-03453, and added IOC URL.

affectedVersionsiocs
via CERT-FR
v7Tier B48d ago

Added affected versions 12.5.0-02835 and 12.4.3-03453, marked exploit as available, and added new tags.

affectedVersionsexploitAvailabletags
via CERT-FR
v6Tier D48d ago

Updated patch version to 12.4.3-03453, added new affected versions, and included indicators of compromise.

affectedVersions
via Heise Security
v5Tier D49d ago

Updated affected versions to include 6210, 7210, and 8200v, added new patch versions, and marked exploit as available.

affectedVersions
via SecurityWeek
v4Tier C49d ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v3Tier D49d ago

Updated to indicate that the vulnerability is actively exploited, added new affected versions, and provided specific indicators of compromise.

affectedVersions
via BleepingComputer
v2Tier B49d ago

Updated affected versions, changed severity to CRITICAL, marked as actively exploited, and noted that exploits are available.

affectedVersionscweIds
via CCCS Canada
v149d ago

Initial creation