Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws
CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug patched in mid-July. Around 380 appliances are still sitting online.

Key points
- CISA confirmed in a fresh update to its Known Exploited Vulnerabilities catalog that ransomware gangs are exploiting two SonicWall SMA1000 flaws, CVE-2026-15409 and CVE-2026-15410.
- SonicWall patched both bugs in mid-July after warning they were already being used in zero-day attacks.
- Incident response firm Volexity traced exploitation back to at least 22 June, weeks before SonicWall went public.
- Shadowserver still counts more than 380 SMA1000 appliances exposed to the public internet.
- CISA ordered federal civilian agencies on 14 July to patch within three days.
Ransomware gangs have started breaking into corporate networks through two flaws in SonicWall's SMA1000 remote access gateway, a device large companies and government agencies use to let staff connect to internal systems remotely.
CISA added the two bugs to its Known Exploited Vulnerabilities Catalog on 14 July. A fresh update now flags them as actively used in ransomware attacks. The agency hasn't named which crews are involved.
What are the flaws?
Both affect the SMA1000, a hardware appliance that acts as a secure front door to a company's internal network. The more serious, CVE-2026-15409, is a maximum-severity server-side request forgery bug: it lets an attacker trick the appliance into making network requests on their behalf to reach systems that should be off-limits. CVE-2026-15410 was patched in the same July advisory.
SonicWall's security team said it had investigated "multiple cases indicating the active exploitation of the vulnerabilities" and told customers to install the hotfix immediately.
| Detail | Value |
|---|---|
| Affected product | SonicWall SMA1000 |
| CVEs | CVE-2026-15409, CVE-2026-15410 |
| Patch released | Mid-July |
| Earliest known exploitation | 22 June |
| Appliances still exposed online | 380+ (Shadowserver) |
| CISA KEV added | 14 July |
Who was hitting these boxes first?
A group Volexity tracks as UTA0533, weeks before the public knew the flaws existed. As first reported by BleepingComputer, Volexity traced attacks to 22 June, when UTA0533 used the two bugs as zero-days, meaning holes the vendor didn't yet know about. Our earlier story on 20 July covers how that access unfolded: criminals planted hidden malware inside the appliances at least three weeks before SonicWall knew the attack routes existed.
Once inside, the attackers deployed custom malware: KNUCKLEBALL, Sou5, ROOTRUN and ORANGETAIL. That toolset points to quiet, long-term access of the kind that gets handed to a ransomware crew later. CISA's update suggests exactly that handover has now happened.
How bad is the exposure right now?
Shadowserver still sees over 380 SMA1000 appliances reachable online. Some may already be patched. Many won't be. Federal civilian agencies were given three days to fix theirs. Private companies have no such deadline, and that's historically where ransomware damage concentrates.
Since we first covered these bugs on 14 July, the picture has only worsened: a named ransomware group, INC, is now cold-calling victims after encrypting their files.
Should you worry?
If you run an SMA1000 that was internet-facing before the patch, yes. Install the July hotfix now, treat any unpatched appliance as potentially backdoored, and hunt for the four malware families Volexity named. Rotate VPN credentials and check logs for unusual internal traffic originating from the appliance itself.
This isn't SonicWall's first rough patch this year. In December the company warned customers about CVE-2025-40602, a flaw in the SMA1000 management console that attackers chained to gain root access. Separately, in September it pushed a firmware update to remove a rootkit called OVERSTEP from SMA 100 series devices. Customers relying on SonicWall for remote access have had a difficult twelve months, and the ransomware confirmation means the worst of it may still be arriving.



