Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws

CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug patched in mid-July. Around 380 appliances are still sitting online.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A network rack in a corporate server room showing a SonicWall appliance with its indicator lights glowing, surrounded by layers of other security hardware, cabl
Share

Key points

  • CISA confirmed in a fresh update to its Known Exploited Vulnerabilities catalog that ransomware gangs are exploiting two SonicWall SMA1000 flaws, CVE-2026-15409 and CVE-2026-15410.
  • SonicWall patched both bugs in mid-July after warning they were already being used in zero-day attacks.
  • Incident response firm Volexity traced exploitation back to at least 22 June, weeks before SonicWall went public.
  • Shadowserver still counts more than 380 SMA1000 appliances exposed to the public internet.
  • CISA ordered federal civilian agencies on 14 July to patch within three days.

Ransomware gangs have started breaking into corporate networks through two flaws in SonicWall's SMA1000 remote access gateway, a device large companies and government agencies use to let staff connect to internal systems remotely.

CISA added the two bugs to its Known Exploited Vulnerabilities Catalog on 14 July. A fresh update now flags them as actively used in ransomware attacks. The agency hasn't named which crews are involved.

What are the flaws?

Both affect the SMA1000, a hardware appliance that acts as a secure front door to a company's internal network. The more serious, CVE-2026-15409, is a maximum-severity server-side request forgery bug: it lets an attacker trick the appliance into making network requests on their behalf to reach systems that should be off-limits. CVE-2026-15410 was patched in the same July advisory.

SonicWall's security team said it had investigated "multiple cases indicating the active exploitation of the vulnerabilities" and told customers to install the hotfix immediately.

Detail Value
Affected product SonicWall SMA1000
CVEs CVE-2026-15409, CVE-2026-15410
Patch released Mid-July
Earliest known exploitation 22 June
Appliances still exposed online 380+ (Shadowserver)
CISA KEV added 14 July

Who was hitting these boxes first?

A group Volexity tracks as UTA0533, weeks before the public knew the flaws existed. As first reported by BleepingComputer, Volexity traced attacks to 22 June, when UTA0533 used the two bugs as zero-days, meaning holes the vendor didn't yet know about. Our earlier story on 20 July covers how that access unfolded: criminals planted hidden malware inside the appliances at least three weeks before SonicWall knew the attack routes existed.

Once inside, the attackers deployed custom malware: KNUCKLEBALL, Sou5, ROOTRUN and ORANGETAIL. That toolset points to quiet, long-term access of the kind that gets handed to a ransomware crew later. CISA's update suggests exactly that handover has now happened.

How bad is the exposure right now?

Shadowserver still sees over 380 SMA1000 appliances reachable online. Some may already be patched. Many won't be. Federal civilian agencies were given three days to fix theirs. Private companies have no such deadline, and that's historically where ransomware damage concentrates.

Since we first covered these bugs on 14 July, the picture has only worsened: a named ransomware group, INC, is now cold-calling victims after encrypting their files.

Should you worry?

If you run an SMA1000 that was internet-facing before the patch, yes. Install the July hotfix now, treat any unpatched appliance as potentially backdoored, and hunt for the four malware families Volexity named. Rotate VPN credentials and check logs for unusual internal traffic originating from the appliance itself.

This isn't SonicWall's first rough patch this year. In December the company warned customers about CVE-2025-40602, a flaw in the SMA1000 management console that attackers chained to gain root access. Separately, in September it pushed a firmware update to remove a rootkit called OVERSTEP from SMA 100 series devices. Customers relying on SonicWall for remote access have had a difficult twelve months, and the ransomware confirmation means the worst of it may still be arriving.

© 2026 Threat Vectr