Skip to content
SonicWallCVE-2026-15410

SonicWall SMA1000: code injection

High7.2CVE-2026-15410 · Published Jul 14, 2026 · updated Jul 16, 2026

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

SonicWall advisory

Affected versions

PackageAffectedFixed in
SMA1000
Product
>= 12.4.3-03245, <= 12.4.3-03434No fix yet
>= 12.5.0-02283, <= 12.5.0-02800No fix yet
Details and references

More SonicWall advisories

All SonicWall
Advisory
SonicWall GMS: unsafe deserialization
High8.4Aug 11
SonicWall GMS: cross-site scripting
Medium6.1Aug 11
SonicWall GMS: remote code execution
Critical9.1Aug 11
SonicWall Global VPN Client: out-of-bounds read
Medium5.5Aug 7
SonicWall SonicOS: remote attacker could manipulate the Host header
Medium6.5Aug 5
SonicWall SMA1000: server-side request forgery
Critical10.0Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.