1. Executive summary
SonicWall has disclosed CVE-2026-15410, a post-authentication code injection vulnerability (CVSS 7.2 HIGH, CWE-94) in the SMA1000 Appliance Management Console (AMC) that permits a remote authenticated administrator to execute arbitrary OS commands on the underlying Linux platform. The vulnerability affects SMA1000 firmware versions 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. Per Help Net Security reporting, CVE-2026-15410 is being actively exploited in the wild alongside CVE-2026-15409 (a separate unauthenticated SSRF flaw in the same product line); however, per the verified reference data, CVE-2026-15410 is NOT listed in CISA KEV at time of writing. EMEA financial services organisations exposing SMA1000 appliances, particularly as perimeter VPN/remote-access gateways face risk of appliance compromise, credential theft, and network bridging if administrator credentials are obtained or reused.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | Active exploitation of a perimeter remote-access appliance (SMA1000) requiring detection, containment, and forensics triage. | Entities must invoke their ICT incident management process to identify affected SMA1000 assets, assess compromise, and execute containment/re-imaging procedures. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A CVSS 7.2 HIGH vulnerability under active exploitation on a critical remote-access gateway. | Incidents resulting from exploitation must be classified per the entity's taxonomy; compromise of a perimeter VPN gateway likely meets major-incident thresholds. |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | If exploitation is confirmed on a financial-entity-managed SMA1000, the incident may qualify as major. | Trigger reporting timelines to competent authorities if a major ICT-related incident is confirmed. |
| DORA Art. 24: digital operational resilience testing — general requirements | SMA1000 appliances are internet-exposed remote-access infrastructure with a known exploitable code injection flaw. | Entities should verify that vulnerability scanning and patch-management programmes cover this appliance class and that internet exposure is validated. |
| NIS2 Art. 21(2)(d): supply chain security measures | Vulnerability originates in a third-party vendor product (SonicWall SMA1000) forming part of the ICT supply chain. | In-scope NIS2 entities must ensure vendor vulnerability management and patch application are integrated into supply-chain security measures. |
| NIS2 Art. 23: incident reporting obligations | Active exploitation of a critical network appliance may constitute a significant incident under NIS2. | NIS2 in-scope organisations must assess whether exploitation triggers significant-incident reporting obligations. |
| UK NIS 2018: UK Network and Information Systems Regulations — OES/RDSP duties | Remote-access gateway compromise could impact the availability and integrity of operator-of-essential-services infrastructure. | UK OES/RDSP organisations should assess whether SMA1000 compromise triggers NIS incident-notification duties. |
3. Technical analysis & attack chain
Affected products and versions (from NVD/CVE record)
- Vendor: SonicWall
- Product: SMA1000
- Platform: Linux
- Affected versions:
- 12.4.3-03245 through 12.4.3-03434 (inclusive)
- 12.5.0-02283 through 12.5.0-02800 (inclusive)
Vulnerability mechanism
The flaw is a post-authentication improper control of generation of code (CWE-94, Code Injection) in the SMA1000 Appliance Management Console (AMC). Under specific conditions, a remote authenticated attacker holding administrator privileges can inject and execute arbitrary OS commands on the appliance's underlying Linux operating system. The attack requires valid administrative credentials; it is not exploitable by unauthenticated users via this CVE alone.
Attack chain (confirmed steps)
- Initial access — credential acquisition: The attacker obtains valid administrator credentials for the SMA1000 AMC. This may occur through credential reuse, phishing of an administrator, brute-force if MFA is not enforced, or — critically — through exploitation of the companion vulnerability CVE-2026-15409 (SSRF, CVSS not assessed in verified data), which is reported as actively exploited and could potentially be chained to facilitate access. Note: CVE-2026-15409 is a distinct vulnerability; chaining is plausible but not confirmed in the source material.
- Authentication to AMC: The attacker authenticates to the SMA1000 Appliance Management Console as administrator.
- Code injection: Via the AMC interface, the attacker injects crafted input that is improperly handled during code generation/execution, resulting in arbitrary OS command execution on the Linux host.
- Post-exploitation: With OS-level command execution, the attacker can establish persistence, harvest credentials and TOTP secrets stored on the appliance, pivot to internal networks accessible through the VPN, or exfiltrate configuration data.
Companion vulnerability context (single-sourced; verify before enforcement)
Help Net Security reports that CVE-2026-15410 is being actively exploited in the wild alongside CVE-2026-15409, a server-side request forgery vulnerability in the same SMA1000 product line that allows a remote unauthenticated attacker to cause the appliance to make requests to unintended locations. The combination of an unauthenticated SSRF (CVE-2026-15409) and a post-authentication code injection (CVE-2026-15410) on the same appliance class increases the likelihood of full unauthenticated compromise if chained. This active-exploitation claim is single-sourced (Help Net Security); the verified CISA KEV data confirms CVE-2026-15409 IS in CISA KEV (due date 2026-07-17) but CVE-2026-15410 is NOT in CISA KEV at time of writing.
Attribution: No threat actor attribution is provided in any source material. No MITRE ATT&CK actor profile is available. Attribution is unconfirmed.
Observed impact: SonicWall advises that if IOCs are present, organisations should re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset TOTP tokens — indicating the vendor assesses that compromise can result in credential and MFA-secret theft sufficient to require full appliance rebuild.
4. Mitigation & containment
P1 — Within 24 hours
- Inventory and exposure assessment: Identify all SonicWall SMA1000 appliances in the estate. Determine firmware version. Confirm whether each appliance is internet-exposed. Prioritise internet-facing instances running affected firmware (12.4.3-03245–12.4.3-03434 or 12.5.0-02283–12.5.0-02800).
- Restrict AMC access: If operationally feasible, restrict access to the Appliance Management Console to trusted internal management networks only (VPN, jump host, management VLAN). Block external access to the AMC interface at the firewall/WAF layer until patched.
- Enforce MFA and credential hygiene: Verify that MFA/TOTP is enforced for all administrator accounts. Rotate administrator credentials if any suspicion of compromise exists. Do not reuse credentials across SMA1000 appliances.
- Review for CVE-2026-15409 exposure: Since CVE-2026-15409 (SSRF) is confirmed in CISA KEV and is reported as actively exploited alongside this CVE, assess exposure to both vulnerabilities simultaneously.
P2 — Within 72 hours
- Apply vendor firmware update: Upgrade all affected SMA1000 appliances to a fixed firmware version. Refer to the SonicWall PSIRT advisory at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 for the specific fixed-version targets and patch instructions.
- Forensic triage: On all appliances running affected firmware — especially internet-facing instances — search for evidence of compromise per SonicWall's published IOC guidance. Key actions: - Review AMC access logs for anomalous administrator sessions (unexpected source IPs, unusual times, repeated authentication events). - Inspect for unexpected OS-level processes, scheduled tasks, or files on the appliance filesystem. - Check for signs of credential or TOTP-secret extraction.
- If compromise is suspected or confirmed: Re-image the hardware appliance or re-deploy the virtual appliance from a known-good baseline. Do not attempt in-place remediation. After rebuild: - Change all user and administrator passwords. - Reset all TOTP tokens. - Re-enrol MFA for all accounts. - Review VPN session logs for the period of potential exposure to identify any suspicious internal-network access.
P3 — Within 7 days
- Validate patch deployment: Confirm all SMA1000 appliances are running fixed firmware via automated inventory scan or management platform reporting.
- Update EDR/network monitoring: Deploy detection rules (see §6) to SIEM and network monitoring platforms. Configure alerts for AMC access from non-management-network sources.
- Review third-party risk: If SMA1000 appliances are managed by an MSSP or ICT third-party provider, confirm patch status and incident-response obligations under the contract (DORA Art. 30).
- Document for regulatory readiness: Record vulnerability identification, assessment, and remediation actions to support DORA Art. 17/18/19 and NIS2 Art. 23 compliance evidence.
5. Indicators of compromise
No indicators of compromise available in the source material. SonicWall references IOCs in its advisory but specific IOC values (hashes, IPs, domains, file paths) were not included in the provided source content. Refer directly to https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 for the current IOC list.
6. Detection
Insufficient indicators to author detection rules. The source material does not contain specific file paths, command-line strings, mutex names, registry keys, network indicators, or process names that could be used to construct YARA or Sigma rules. Analysts should monitor for:
- Anomalous administrator authentication events to the SMA1000 AMC (unexpected source IPs, off-hours access).
- Outbound network connections from the SMA1000 appliance to unexpected destinations (potential CVE-2026-15409 SSRF indicator).
- OS-level process execution on the appliance inconsistent with normal AMC operations.
Refer to the SonicWall PSIRT advisory (https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008) for vendor-published detection guidance and IOCs.
CVE assessment
1 referenced CVE
| CVE | CVSS | Exploited | EPSS | Summary |
|---|---|---|---|---|
| CVE-2026-15410 | 7.2 High | — | — | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000… |
7. Sources
- NVD — CVE-2026-15410 Detail — https://nvd.nist.gov/vuln/detail/CVE-2026-15410 — Published 2026-07-14
- SonicWall PSIRT — SNWLID-2026-0008 — https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 — Referenced in NVD CVE record
- Help Net Security — SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) — https://www.helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-2026-15410/ — Published 2026-07-14
- CISA KEV — CVE-2026-15409 (companion vulnerability) — https://nvd.nist.gov/vuln/detail/CVE-2026-15409 — Due date 2026-07-17
8. Adverse Trace position
CVE-2026-15410 is a CVSS 7.2 HIGH post-authentication code injection vulnerability in a perimeter remote-access appliance — a high-value target for threat actors seeking to bridge into internal networks. The requirement for administrator credentials lowers the standalone severity, but the reported active exploitation alongside CVE-2026-15409 (an unauthenticated SSRF confirmed in CISA KEV) materially elevates the combined risk: an attacker could potentially leverage the SSRF to facilitate access and then use this code injection for full OS-level control. The verified reference data confirms CVE-2026-15410 is NOT yet in CISA KEV, but the companion CVE-2026-15409 IS, with a remediation due date of 2026-07-17. The active-exploitation claim for CVE-2026-15410 is single-sourced (Help Net Security); we assess it as credible given the vendor's explicit guidance to perform forensic triage and full appliance re-imaging if IOCs are present, but clients should verify against the SonicWall PSIRT advisory before enforcement actions. No threat actor attribution is available. EMEA financial services clients with internet-facing SMA1000 appliances should treat this as a P1 priority: restrict AMC exposure, patch within 72 hours, and perform forensic triage on all affected instances. Adverse Trace will monitor for CISA KEV addition, IOC publication, and any emerging attribution reporting.
Published via PulseTrace — Adverse Trace threat intelligence.