Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.2
CVE-2026-15410EXPLOITEDPATCHED
sonicwall · sma6210_firmware

CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Affected Products

VendorProductVersions
sonicwallsma6210_firmware12.4.3-03245, 12.5.0-02283

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallsmacert_advisory90%
sonicwallsma7210_firmwarecve_cpe95%
sonicwallsma8200vcve_cpe95%
sonicwallsma6210cve_cpe95%
sonicwallsma7210cve_cpe95%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008(vendor-advisory)

Related News (24 articles)

Tier D
BleepingComputer13d ago
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
→ No new info (linked only)
Tier D
The Hacker News20d ago
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
→ No new info (linked only)
Tier C
Rapid7 Blog24d ago
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
→ No new info (linked only)
Tier C
Rapid7 Blog26d ago
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
→ No new info (linked only)
Tier D
Help Net Security28d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier D
BleepingComputer32d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
→ No new info (linked only)
Tier C
Rapid7 Blog32d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
Help Net Security33d ago
SonicWall SMA zero-days were exploited weeks before disclosure
→ No new info (linked only)
Tier D
BleepingComputer34d ago
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
→ No new info (linked only)
Tier D
SecurityWeek34d ago
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
→ No new info (linked only)
Tier D
The Hacker News34d ago
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
→ No new info (linked only)
Tier D
The Hacker News35d ago
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
→ No new info (linked only)
Tier D
Help Net Security36d ago
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
→ No new info (linked only)
Tier E
Hacker News39d ago
CVE-2026-15409: SonicWall SMA 1000 SSRF Zero-Day
→ No new info (linked only)
Tier C
Rapid7 Blog39d ago
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
→ No new info (linked only)
Tier B
BSI Advisories39d ago
[NEU] [kritisch] SonicWall SMA: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security39d ago
SonicWall SMA1000: Angriffe auf teils kritische Zero-Day-Lücken
→ No new info (linked only)
Tier D
SecurityWeek40d ago
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-15410 | SonicWall SMA1000 up to 12.4.3-03434/12.5.0-02800 Management Console code injection
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans Secure Mobile Access (15 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans Sonicwall Secure Mobile Access 1000 (15 juillet 2026)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity40d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier D
BleepingComputer40d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
→ No new info (linked only)
Tier B
CCCS Canada40d ago
SonicWall security advisory (AV26-699) – Update 1
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
CWECWE-94
PublishedJul 14, 2026
Last enriched34d agov12
Tags
SonicWallSecure Mobile AccessZero-DayUTA0533Chained with CVE-2026-15409KEV CatalogKnuckleBall malwareOrangeTail webshellSuo5 proxy
Trending Score15
Source articles24
Independent12
Info Completeness11/14
Missing: epss, kev, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 45
CRITICALCVE-2026-66147
CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
Trending: 16
CRITICALCVE-2026-66145
CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
Trending: 16
HIGHCVE-2026-66149
CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 13
HIGHCVE-2026-66150
CVE-2026-66150: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 13

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, cweIds
Jul 14, 2026
Updated: affectedVersions
Jul 14, 2026
Updated: severity, activelyExploited
Jul 15, 2026
Updated: affectedVersions
Jul 15, 2026
Updated: affectedVersions
Jul 15, 2026
Updated: affectedVersions, exploitAvailable, tags
Jul 15, 2026
Updated: affectedVersions, iocs
Jul 15, 2026
Updated: affectedVersions, tags
Jul 15, 2026
Updated: tags
Jul 20, 2026
Updated: tags
Jul 20, 2026
Updated: affectedVersions, description
Jul 20, 2026
Actively Exploited
Aug 4, 2026
Exploit Available
Aug 4, 2026
Patch Available
Aug 4, 2026

Version History

v12
Last enriched 34d ago
v12Tier D34d ago

Added patched versions (12.4.3-03453, 12.5.0-02835) and significantly expanded description with technical exploitation details including the attack chain, RPC method exploited, and malware payload information.

affectedVersionsdescription
via BleepingComputer
v11Tier D34d ago

Added malware artifacts (KnuckleBall, OrangeTail, Suo5) deployed post-exploitation and KEV Catalog tag; confirmed remote unauthenticated attack vector contrary to previous authentication requirement in description.

tags
via SecurityWeek
v10Tier D34d ago

Added threat actor attribution (UTA0533) and confirmation that CVE-2026-15410 was exploited as a zero-day since June 22, 2026, chained with CVE-2026-15409 for command execution.

tags
via The Hacker News
v9Tier C39d ago

Updated description with technical details, added new affected versions, and included new relevant tags.

affectedVersionstags
via Rapid7 Blog
v8Tier B39d ago

Updated affected versions to include 12.5.x prior to 12.5.0-02835 and 12.4.3 prior to 12.4.3-03453, and added IOC URL.

affectedVersionsiocs
via CERT-FR
v7Tier B39d ago

Added affected versions 12.5.0-02835 and 12.4.3-03453, marked exploit as available, and added new tags.

affectedVersionsexploitAvailabletags
via CERT-FR
v6Tier D39d ago

Updated patch version to 12.4.3-03453, added new affected versions, and included indicators of compromise.

affectedVersions
via Heise Security
v5Tier D40d ago

Updated affected versions to include 6210, 7210, and 8200v, added new patch versions, and marked exploit as available.

affectedVersions
via SecurityWeek
v4Tier C40d ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v3Tier D40d ago

Updated to indicate that the vulnerability is actively exploited, added new affected versions, and provided specific indicators of compromise.

affectedVersions
via BleepingComputer
v2Tier B40d ago

Updated affected versions, changed severity to CRITICAL, marked as actively exploited, and noted that exploits are available.

affectedVersionscweIds
via CCCS Canada
v140d ago

Initial creation