Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws
CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug that has been patched since mid-July. Roughly 380 appliances are still sitting online.

Key points
- The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on updates to its Known Exploited Vulnerabilities list that ransomware gangs are now exploiting two SonicWall SMA1000 flaws, CVE-2026-15409 and CVE-2026-15410.
- SonicWall patched both bugs in mid-July after warning they were already being used in zero-day attacks.
- Incident response firm Volexity traced exploitation back to at least June 22, weeks before SonicWall went public.
- Internet scanning group Shadowserver still counts more than 380 SMA1000 appliances exposed to the public internet.
- CISA ordered federal civilian agencies on July 14 to patch within three days.
Ransomware gangs have started breaking into corporate networks through two flaws in SonicWall's SMA1000 remote access gateway, a device many large companies and government agencies use to let staff connect to internal systems from home.
CISA added the two bugs to its Known Exploited Vulnerabilities Catalog on July 14 and has now flagged them as being used in ransomware attacks in a fresh update.
The agency did not name which ransomware crews are involved.
What are the flaws?
Two vulnerabilities in the SMA1000, a piece of hardware that acts as a secure front door to a company's internal network. The more serious one, CVE-2026-15409, is a maximum-severity server-side request forgery bug, which lets an attacker trick the appliance into making network requests on their behalf and reach systems that should be off-limits. The second, CVE-2026-15410, was patched in the same July advisory.
SonicWall's own security team said at the time it had investigated "multiple cases indicating the active exploitation of the vulnerabilities" and told customers to install the hotfix immediately.
| Detail | Value |
|---|---|
| Affected product | SonicWall SMA1000 |
| CVEs | CVE-2026-15409, CVE-2026-15410 |
| Patch released | Mid-July |
| Earliest known exploitation | 22 June |
| Appliances still exposed online | 380+ (Shadowserver) |
| CISA KEV added | 14 July |
Who was hitting these boxes first?
A group that Volexity tracks as UTA0533, weeks before the public even knew the flaws existed. As first reported by BleepingComputer, Volexity traced attacks back to 22 June, when the group used the two bugs as zero-days, meaning holes the vendor did not yet know about.
Once inside, the hackers dropped custom malware named KNUCKLEBALL, Sou5, ROOTRUN and ORANGETAIL onto the appliances. That kind of tooling is normally used for quiet, long-term access, the sort of foothold that later gets sold on or handed to a ransomware crew.
CISA's latest update suggests exactly that handover has happened.
How bad is the exposure right now?
Bad enough. Shadowserver, which scans the public internet for vulnerable kit, still sees over 380 SMA1000 appliances reachable online. Some of those may already be patched. Many will not be.
Federal civilian agencies in the US were given three days to fix theirs. Private companies have no such deadline, which is usually where the ransomware damage lands.
What should affected organisations do?
Install SonicWall's July hotfix if you have not already. Assume any SMA1000 that was exposed to the internet before the patch went on may already be back-doored, and hunt for the malware families Volexity named: KNUCKLEBALL, Sou5, ROOTRUN, ORANGETAIL. Rotate VPN credentials and check logs for unusual internal traffic coming from the appliance itself.
This is not SonicWall's first bad quarter. In December the company patched CVE-2025-40602 in the SMA1000 management console after attackers chained it to gain root access. In September it pushed firmware to strip out a rootkit called OVERSTEP from SMA 100 series devices. Customers using SonicWall as their remote access front door have had a rough year.

