CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.
SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks.
"SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," the company warned at the time. "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities."
Incident response firm Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed online, although some may already have been secured against attacks.
SonicWall SMA1000 instances exposed online (Shadowserver)The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the cybersecurity agency said.
SonicWall has yet to update its original advisory to confirm that CVE-2026-15409 and CVE-2026-15410 are targeted in ransomware attacks, but CISA has now also flagged them as exploited by ransomware gangs in recent updates to the KEV Catalog.
While the cybersecurity agency didn't provide additional information on these attacks, cybersecurity firm Resecurity has linked the attacks to an INC Ransomware affiliate.
In December, the company warned customers to patch another vulnerability (CVE-2025-40602) in the SonicWall SMA1000 Appliance Management Console (AMC) that was being chained by hackers in zero-day attacks to gain root privileges.
One month earlier, SonicWall linked state-sponsored hackers to a September security breach that exposed customers' firewall configuration backup files after researchers warned of over 100 SonicWall SSLVPN accounts compromised using stolen credentials.
In September, it also pushed a firmware update to help remove OVERSTEP rootkit malware deployed in attacks targeting SMA 100 series devices.
References in this story
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now www.bleepingcomputer.com SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates.
- The AI Security Starter Pack (Free Download) | Wiz wiz.io Wiz is the unified cloud security platform with prevention and response capabilities, enabling security and development teams to build faster and more securely.
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware www.bleepingcomputer.com Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
- Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
- Security Advisory psirt.global.sonicwall.com
- Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
- Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
- Resecurity | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain www.resecurity.com
- Sonicwall warns of new SMA1000 zero-day exploited in attacks www.bleepingcomputer.com SonicWall warned customers today to patch a vulnerability in the SonicWall SMA1000 Appliance Management Console (AMC) that was chained in zero-day attacks to escalate privileges.
- SonicWall says state-sponsored hackers behind September security breach www.bleepingcomputer.com SonicWall's investigation into the September security breach that exposed customers' firewall configuration backup files concludes that state-sponsored hackers were behind the attack.
- SonicWall warns customers to reset credentials after breach www.bleepingcomputer.com SonicWall warned customers today to reset credentials after their firewall configuration backup files were exposed in a security breach that impacted MySonicWall accounts.
- SonicWall VPN accounts breached using stolen creds in widespread attacks www.bleepingcomputer.com Researchers warn that threat actors have compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen, valid credentials.
- SonicWall releases SMA100 firmware update to wipe rootkit malware www.bleepingcomputer.com SonicWall has released a firmware update that can help customers remove rootkit malware deployed in attacks targeting SMA 100 series devices.
- SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware www.bleepingcomputer.com A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances.



