CVE-2026-15410 is a post-authentication code injection flaw (CWE-94) in the Appliance Management Console (AMC) of SonicWall SMA 1000 series appliances. It is triggered when a remote attacker with valid administrator credentials accesses the AMC under specific conditions, allowing arbitrary OS command execution on the appliance. Successful exploitation yields full command execution with the privileges of the appliance, enabling data theft, credential harvesting, lateral movement, and — per CISA — use in ransomware operations. Organizations running SMA 1000 appliances (SMA 6210, SMA 7210, SMA 8000v) are affected. The flaw is being actively exploited in the wild as a zero-day, reportedly alongside a companion SMA 1000 zero-day (CVE-2026-15409) with which it may form an attack chain; it was added to the CISA KEV catalog on 2026-07-14, and EPSS (11.8%, 96th percentile) indicates elevated near-term exploitation risk.
What to do: Apply the SonicWall SMA 1000 firmware update addressing CVE-2026-15410 (and the related CVE-2026-15409) as soon as the vendor fix is published, following SonicWall's advisory instructions and CISA BOD 26-04 requirements if applicable. Until patched, restrict AMC access to trusted management networks rather than the public internet, verify which administrator accounts have AMC access, and review appliances for signs of compromise given known ransomware use — follow CISA's Forensics Triage Requirements for federal assets.
Affected
SonicWall SMA1000 Appliance Management Console (AMC) — SMA 6210
—
SonicWall SMA1000 Appliance Management Console (AMC) — SMA 7210
moderate≈several thousand to ~10,000 internet-exposed SMA 1000 appliances, with a total installed base likely larger — The SMA 1000 series is a niche enterprise remote-access line (SMA 6210/7210/8000v) whose AMC is frequently exposed for management; public internet scans of this product family have historically shown devices in the thousands, so the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CISA Known Exploited Vulnerability
Affected
SonicWall SMA1000 Appliances
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
SonicWall patches two actively exploited SMA 1000 VPN zero-days: CVSS 10.0 pre-auth SSRF CVE-2026-83548 and post-auth command injection CVE-2026-83549, chained for RCE.
SonicWall released hotfixes for two zero-day vulnerabilities in its SMA 1000 VPN appliances, with SonicWall PSIRT confirming active exploitation in the wild. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF in the Appliance Work Place interface allowing unauthenticated unauthorized operations; CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection in the Appliance Management Console enabling arbitrary command execution and RCE. The flaws affect models 6210, 7210 and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier, fixed in versions 12.4.3-03526 and 12.5.0-02952. This follows a July Volexity report on threat actor UTA0533 chaining two SMA 1000 zero-days to gain root access and deploy the KNUCKLEBALL Python backdoor.
SonicWall patches two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 VPN appliances, likely chained for code execution.
SonicWall fixed CVE-2026-83548 (CVSS 10.0), a pre-authentication SSRF in the Appliance Work Place interface, and CVE-2026-83549 (CVSS 7.8), a post-authentication OS command injection in the Appliance Management Console. The company investigated a case indicating active exploitation, suggesting attackers chained both bugs to execute arbitrary code on susceptible devices. Affected SMA 1000 models 6210, 7210, and 8200v require hotfixes 12.4.3-03526 or 12.5.0-02952; customers are urged to hunt for IoCs and re-image, reset credentials, and rotate TOTP if found.