CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
- CVSS
- 7.2 (High)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Coordinate with the CVE-2026-15409 change window — single SMA1000 firmware update addresses both.
- Vendor advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- Affected products
- SonicWall SMA1000 Appliances
Why this one matters to a CAB
The authenticated-admin code injection in the same SMA1000 advisory gets less attention than its unauthenticated sibling (CVE-2026-15409), but it matters for a different reason: it is the post-exploitation lever an attacker who already phished an SMA administrator will use to persist. Chained with the SSRF, the pair converts a perimeter box into a durable foothold.
Defender’s angle
- MFA on the admin plane: SonicWall’s SMA admin console must require MFA. If yours does not today, that is a bigger finding than this CVE; fix it in the same change window.
- Command-line log: the SMA1000 CLI history is short by default. Increase its retention before the patch window so post-patch investigations have a baseline.
- Package with CVE-2026-15409: one firmware upgrade fixes both.
What to bring to CAB
The combined firmware upgrade change record from the CVE-2026-15409 entry, updated to explicitly cite this CVE as an in-scope authenticated-admin code injection so the risk narrative captures both.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.