CISA_KEV · JULY 2026 · CONFIRMED

SonicWall SMA1000 Appliances Exploited: CVE-2026-15410 Confirmed

CVE-2026-15410Severity: HIGH

SonicWall SMA1000 Appliances are affected by a high-severity code injection vulnerability, CVE-2026-15410, which has been exploited in zero-day attacks. Users should contact SonicWall for a patch or workaround.

What happened

SonicWall has confirmed that its SMA1000 Appliances are vulnerable to a code injection flaw, tracked as CVE-2026-15410. This vulnerability, when exploited, allows a remote authenticated attacker with administrator privileges to execute arbitrary operating system commands. The severity of this vulnerability is high, with a CVSS score of 7.2. However, due to the potential impact, SonicWall has assigned an overall CVSS score of 10.0 to the advisory.

The vulnerability has been actively exploited in zero-day attacks, as reported by multiple independent sources including BleepingComputer and SecurityWeek. Attackers have been using this flaw to deliver custom malware. SonicWall urges all customers using SMA1000 Appliances to install the newly released security updates immediately.

To assess your exposure, check if you are using SonicWall SMA1000 Appliances. If so, verify that you have applied the latest security updates provided by SonicWall. For more detailed information and to obtain the necessary patches, contact SonicWall directly. Primary sources should be consulted for the most current and specific details regarding this vulnerability.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If sonicwall-sma1000 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats