Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Is CVE-2026-15410 exploited?
Listed in the CISA KEV catalog on 2026-07-14.
Federal remediation due 2026-07-17.
Past that date by 29 days.
Public exploit code: none found in monitored sources.