SonicWall SMA1000 high-severity code injection vulnerability (CVE-2026-15410) allows authenticated RCE. Actively exploited and KEV-listed.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| sma6210_firmware | 12.4.3-03245 | 12.4.3-03245 | vulnerable |
| sma6210_firmware | 12.4.3-03387 | 12.4.3-03387 | vulnerable |
| sma6210_firmware | 12.4.3-03434 | 12.4.3-03434 | vulnerable |
| sma6210_firmware | 12.5.0-02283 | 12.5.0-02283 | vulnerable |
| sma6210_firmware | 12.5.0-02624 | 12.5.0-02624 | vulnerable |
| sma6210_firmware | 12.5.0-02800 | 12.5.0-02800 | vulnerable |
| sma6210 | - | - | unaffected |
| sma7210_firmware | 12.4.3-03245 | 12.4.3-03245 | vulnerable |
| sma7210_firmware | 12.4.3-03387 | 12.4.3-03387 | vulnerable |
| sma7210_firmware | 12.4.3-03434 | 12.4.3-03434 | vulnerable |
| sma7210_firmware | 12.5.0-02283 | 12.5.0-02283 | vulnerable |
| sma7210_firmware | 12.5.0-02624 | 12.5.0-02624 | vulnerable |
| sma7210_firmware | 12.5.0-02800 | 12.5.0-02800 | vulnerable |
| sma7210 | - | - | unaffected |
| sma8200v | 12.4.3-03245 | 12.4.3-03245 | vulnerable |
| sma8200v | 12.4.3-03387 | 12.4.3-03387 | vulnerable |
| sma8200v | 12.4.3-03434 | 12.4.3-03434 | vulnerable |
| sma8200v | 12.5.0-02283 | 12.5.0-02283 | vulnerable |
| sma8200v | 12.5.0-02624 | 12.5.0-02624 | vulnerable |
| sma8200v | 12.5.0-02800 | 12.5.0-02800 | vulnerable |
| sma8200v | - | - | unaffected |
Download and install the latest firmware updates provided by SonicWall specifically addressing SNWLID-2026-0008 to remediate the code injection flaw in the Appliance Management Console (AMC).
Ensure SMA 6210, 7210, and 8200v appliances are moved beyond vulnerable firmware builds, including 12.4.3-03434 and 12.5.0-02800, to the latest secure release recommended by the vendor.
Limit access to the Appliance Management Console (AMC) interface to trusted internal management networks only and enforce strict Multi-Factor Authentication (MFA) for all administrative accounts to prevent credential abuse.
Conduct a forensic triage as per CISA BOD 26-04 guidelines and review appliance logs for unusual administrative activity, unauthorized OS command execution, or unexpected configuration changes.
"Detecting exploitation of CVE-2026-15410 involves monitoring SonicWall SMA1000 Appliance Management Console (AMC) logs for suspicious POST requests or unusual administrative sessions. Security teams should look for evidence of shell command execution or unexpected outbound network connections originating from the appliance. Additionally, verify the integrity of system files and check for unauthorized administrative account creation or modification, as these may indicate a successful post-authentication breach."
Experience superior visibility and a simpler approach to cyber risk management