{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-15410",
  "revision": 1,
  "title": "SonicWall SMA1000 — admin code injection in management console",
  "summary": "An administrator signed in to the Appliance Management Console (AMC) of SonicWall Secure Mobile Access 1000 (SMA1000) appliances can, under certain conditions, inject code that the appliance runs as operating system (OS) commands.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.2,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.11791,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-07-14",
    "prerequisites": "Valid administrator credentials for the Appliance Management Console, reachable over the network."
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "execution",
  "recommended_action": "Patch SMA1000 per SonicWall SNWLID-2026-0008 now; restrict the management console to a trusted admin network and rotate administrator credentials.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-15410",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008"
    }
  ],
  "published_at": "2026-07-14T20:16:56.903Z",
  "issued_at": "2026-09-23T07:33:20.707Z",
  "tags": [
    "sonicwall",
    "sma1000",
    "code-injection",
    "ransomware",
    "kev"
  ]
}
