AI analysis

CVE-2026-15410 carries a dangerous contradiction: it's classified as post-authentication yet holds a 0.76 EPSS score and KEV status. This combination should not happen. High EPSS scores typically correlate with pre-authentication vulnerabilities, wormable flaws, or exposures in massively-deployed software. Post-auth vulns rarely cross the 0.75 threshold because the authentication barrier is supposed to be the mitigating control.

If this vulnerability is being actively exploited in the wild, treat the 'post-authentication' label as a question, not an answer. Ask instead: how are attackers becoming administrators on these SonicWall SMA100 appliances?

The likely explanations are concerning. Either the AMC (Access Management Console) authentication is routinely bypassed through credential theft, session hijacking, or phishing — or this vulnerability is being chained with an initial compromise to achieve admin-level access. Either way, 'administrator required' is not your shield.

The vague 'specific conditions' qualifier in the advisory is a red flag. When vendors leave attack preconditions unspecified, it typically means the full attack surface hasn't been characterized internally. You cannot properly assess your risk if you don't know what those conditions are.

What to do now: determine whether your AMC interface is internet-facing and, if so, treat it as a critical exposure. Review your logging to ensure admin-level command execution within AMC is captured with sufficient fidelity to detect exploitation attempts. Assume the 'specific conditions' could apply to your environment until proven otherwise.