Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-04 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: high ยท affected_sectors: [] ยท au_impact: false

CVE-2026-15410

Summary

CVE-2026-15410 (CVSS 7.2) is a high-severity vulnerability in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, discovered by Volexity. It was chained with CVE-2026-15409 (CVSS 10.0) by threat actors โ€” including the INC Ransomware operation โ€” to achieve root-level device compromise without authentication.

Details

CVE-2026-15410 (CVSS 7.2) is chained with CVE-2026-15409 (CVSS 10.0) to facilitate arbitrary command execution and full device takeover. The vulnerabilities were exploited as zero-days since at least June 22, 2026, before public disclosure. The INC Ransomware group claimed 885 victims through exploitation of these SMA 1000 flaws.

Remediation

Patches were released by SonicWall in mid-July 2026. Organisations using SMA 1000 series appliances should apply patches immediately.

Related

Sources