Skip to main content
Change Risk Intel

CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CVSS
7.2 (High)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Coordinate with the CVE-2026-15409 change window — single SMA1000 firmware update addresses both.
Affected products
SonicWall SMA1000 Appliances

Why this one matters to a CAB

The authenticated-admin code injection in the same SMA1000 advisory gets less attention than its unauthenticated sibling (CVE-2026-15409), but it matters for a different reason: it is the post-exploitation lever an attacker who already phished an SMA administrator will use to persist. Chained with the SSRF, the pair converts a perimeter box into a durable foothold.

Defender’s angle

  • MFA on the admin plane: SonicWall’s SMA admin console must require MFA. If yours does not today, that is a bigger finding than this CVE; fix it in the same change window.
  • Command-line log: the SMA1000 CLI history is short by default. Increase its retention before the patch window so post-patch investigations have a baseline.
  • Package with CVE-2026-15409: one firmware upgrade fixes both.

What to bring to CAB

The combined firmware upgrade change record from the CVE-2026-15409 entry, updated to explicitly cite this CVE as an in-scope authenticated-admin code injection so the risk narrative captures both.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.