Knox CVE Database
/
CVE-2026-15410
High
7.2
Ransomware use

CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Added to the CISA KEV catalog:
July 14, 2026

Overview

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Vulnerability details

Affected vendor
SonicWall
Affected product
SMA1000 Appliances
Weakness type (CWE)
CWE-94

CVE-2026-15410 is a post-authentication code injection flaw (CWE-94) in the SonicWall SMA1000 Appliance Management Console (AMC). The AMC fails to properly control how attacker-supplied input is incorporated into dynamically generated code. When an administrator submits crafted input to the AMC, that input is processed without adequate sanitization and passed into a code generation path, allowing arbitrary OS commands to be constructed and executed on the underlying appliance. The flaw affects SMA1000 models 6210, 7210, and 8200v across multiple firmware builds in the 12.4.3 and 12.5.0 release lines.


An attacker who holds administrator-level credentials and can reach the AMC interface over the network submits crafted input to the console. Under specific conditions the AMC does not identify in public detail, that input is incorporated into generated code and executed as OS commands on the appliance, yielding full confidentiality, integrity, and availability impact. The precondition of administrator authentication materially limits direct exploitability, though active exploitation has been confirmed in the wild and this vulnerability is associated with known ransomware activity, making credential compromise a realistic precursor.

Severity and impact

7.2
High
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review extraweb_access.log for HTTP 200 responses to /\_\_api\_\_/login or /\_\_api\_\_/logout, and for HTTP 101 responses to /wsproxy with suspicious host parameters. These URIs do not appear in legitimate AMC traffic and are published IOCs for this advisory.
  • Inspect /var/lib/unit/conf.json for routes referencing /\_\_api\_\_/login or /\_\_api\_\_/logout. Their presence in that file indicates configuration tampering and is an explicit IOC identified by SonicWall PSIRT and Volexity.
  • Search ctrl-service.log for hotfix rollback entries containing path traversal strings. Legitimate rollback operations do not include traversal sequences; their presence indicates post-exploitation activity.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 17, 2026

Additional hardening

  • Upgrade SMA1000 models 6210, 7210, and 8200v to firmware 12.4.3-03453 or later (for the 12.4.3 line) or 12.5.0-02835 or later (for the 12.5.0 line). SonicWall confirms no workaround exists; patching is the only remediation. See References for the vendor advisory.
  • Restrict AMC interface access to dedicated management networks or jump hosts. The AMC should not be reachable from general user segments or the public internet, reducing the attack surface even when administrator credentials are compromised.
  • Audit all administrator accounts on affected appliances. Rotate credentials and reset TOTP tokens, particularly if any IOCs are found. If compromise is confirmed, SonicWall recommends re-imaging hardware appliances or redeploying virtual instances rather than attempting in-place remediation.
  • Conduct forensic triage per CISA BOD 26-04 requirements before returning any appliance to service. If IOCs are present in logs or configuration files, treat the appliance as fully compromised and follow the re-image path described in the vendor advisory.

Key dates

Published (NVD)
July 14, 2026
Added to CISA KEV
July 14, 2026
Remediation deadline
July 17, 2026
Last updated
July 16, 2026

References

Frequently asked questions

Does CVE-2026-15410 affect my FedRAMP authorization?

If SonicWall SMA1000 Appliances runs inside your authorization boundary, CVE-2026-15410 affects your FedRAMP authorization directly. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of July 17, 2026. An unpatched KEV within your boundary is a finding your assessor and sponsoring agency will raise. You must either remediate it or formally document a mitigation before that deadline.

How does Knox help me handle CVE-2026-15410?

Knox does not patch SonicWall SMA1000 Appliances on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to own. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that work, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The patch is your responsibility; maintaining a compliant posture while you apply it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-15410 surfaces, exposure is identified through continuous monitoring rather than waiting for an assessor to flag it at a periodic review. That earlier signal gives your team time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-15410 isn't remediated by July 17, 2026?

Missing the July 17, 2026 deadline turns CVE-2026-15410 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting