
CISA has confirmed that ransomware gangs have begun exploiting two not too long ago patched SonicWall SMA1000 vulnerabilities, together with a maximum-severity server-side request forgery (SSRF) flaw.
SMA1000 is an enterprise-grade safe distant entry gateway utilized by massive firms, authorities businesses, and Managed Service Suppliers (MSSPs) to present VPN entry to inner purposes and company networks.
SonicWall launched patches for the 2 safety flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it additionally warned that risk actors had been exploiting them in zero-day attacks.
“SonicWall PSIRT has investigated a number of circumstances indicating the energetic exploitation of the vulnerabilities described on this advisory,” the corporate warned on the time. “Clients are strongly urged to improve to the hotfix launch as quickly as doable to remediate these vulnerabilities.”
Incident response agency Volexity later revealed {that a} risk actor tracked as UTA0533 started exploiting the vulnerabilities as early as June 22 (weeks earlier than SonicWall publicly disclosed the issues) to deploy custom malware often called KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on susceptible VPN home equipment.
Web safety watchdog Shadowserver at the moment tracks over 380 SMA1000 appliances uncovered on-line, though some could have already got been secured in opposition to assaults.

The U.S. Cybersecurity and Infrastructure Safety Company (CISA) added the 2 flaws to its Identified Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Government Department (FCEB) businesses to patch their techniques inside three days.
“The sort of vulnerability is a frequent assault vector for malicious cyber actors and poses vital dangers to the federal enterprise,” the cybersecurity company stated.
SonicWall has but to replace its original advisory to substantiate that CVE-2026-15409 and CVE-2026-15410 are focused in ransomware assaults, however CISA has now additionally flagged them as exploited by ransomware gangs in current updates to the KEV Catalog.
Whereas the cybersecurity company did not present further info on these assaults, cybersecurity agency Resecurity has linked the attacks to an INC Ransomware affiliate.
In December, the corporate warned customers to patch one other vulnerability (CVE-2025-40602) within the SonicWall SMA1000 Equipment Administration Console (AMC) that was being chained by hackers in zero-day assaults to realize root privileges.
One month earlier, SonicWall linked state-sponsored hackers to a September security breach that uncovered clients’ firewall configuration backup information after researchers warned of over 100 SonicWall SSLVPN accounts compromised utilizing stolen credentials.
In September, it additionally pushed a firmware update to assist take away OVERSTEP rootkit malware deployed in assaults focusing on SMA 100 collection units.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remaining transfer via your surroundings unseen.
The Picus whitepaper reveals how breach and assault simulation checks your SIEM and EDR guidelines so threats cease slipping by detection.

