CISA has confirmed that ransomware gangs are actively exploiting two SonicWall SMA1000 flaws, including a maximum-severity SSRF bug, weeks after zero-day attacks began. UK organisations running these remote-access gateways should treat this as an urgent trigger to audit exposure and patch without delay.
View the data behind this chart
| CVE-2026-15409 | CVE-2026-15410 | |
|---|---|---|
| CVSS Score | CVSS10 | CVSS7.2 |
CISA confirms ransomware gangs are now exploiting SMA1000
The US Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-15409 and CVE-2026-15410 as being used in ransomware attacks, not just isolated intrusions. Both flaws affect SonicWall's SMA1000 secure remote access gateway, which large corporates, government bodies and MSSPs use to provide VPN access into internal networks and applications.
SonicWall itself has yet to update its original advisory to name ransomware as an attack vector, but CISA's catalogue update is the clearer signal for defenders. For UK buyers, KEV inclusion tends to be the moment risk committees stop treating a bug as theoretical and start treating it as an active, exploited threat requiring immediate action.
Inside the two flaws now being weaponised
CVE-2026-15409 is a server-side request forgery vulnerability with a maximum CVSS score of 10.0, while CVE-2026-15410 is a post-authentication code injection flaw in the Appliance Management Console rated 7.2. Reporting indicates the two can be chained together to achieve arbitrary command execution, effectively handing an attacker full control of a vulnerable appliance rather than partial access.
SonicWall released hotfixes for both in mid-July 2026 and urged customers to upgrade immediately after confirming active exploitation. The affected models called out in follow-up coverage are the SMA1000 6210, 7210 and 8200v — worth checking against asset inventories now if that hasn't already happened.
A zero-day campaign that predated public disclosure by weeks
Incident response firm Volexity attributed early exploitation to a cluster it tracks as UTA0533, with activity beginning around 22 June 2026 — roughly three weeks before SonicWall's public advisory. That group deployed custom malware named KNUCKLEBALL, Sou5, ROOTRUN and ORANGETAIL onto compromised appliances.
Telemetry cited by Rapid7 points to a more troubling pattern than opportunistic access: attackers reportedly harvested credentials, active session databases and TOTP MFA seed configurations. Stealing MFA seeds in particular suggests intent to maintain durable, stealthy access long after a patch is applied, which is exactly why expert incident response services should be on standby rather than an afterthought.

Why UK remote-access estates should pay close attention
Shadowserver currently tracks more than 380 SMA1000 appliances still exposed to the open internet, some of which may already be patched but many of which are not. SMA1000 is specifically an enterprise and MSSP-grade gateway, meaning a single compromised deployment can expose downstream client networks — a supply-chain risk UK managed service customers should ask their providers about directly.
Recent reporting has named INC Ransomware as the dominant actor now weaponising this vulnerability chain, moving the story beyond a single threat cluster into a broader criminal ecosystem. Organisations relying on SMA1000 for VPN access should treat internet-facing exposure of the appliance itself as a priority item, and consider whether it's time to strengthen your network security posture around remote-access infrastructure generally.
SonicWall's recurring exploitation problem
This is not an isolated incident for SonicWall's remote-access line. In December, the company warned of another SMA1000 Appliance Management Console flaw, CVE-2025-40602, being chained in zero-day attacks to gain root privileges. A month earlier, SonicWall linked state-sponsored hackers to a September breach exposing customers' firewall configuration backup files, following separate warnings about compromised SSLVPN accounts using stolen credentials.
SonicWall also pushed a firmware update in September to help remove OVERSTEP rootkit malware from SMA 100 series devices targeted in earlier attacks. Taken together, this pattern suggests SonicWall's remote-access appliances have become a repeat target, which should factor into any vendor risk review or renewal decision alongside support for your IT infrastructure.
What UK security and IT leaders should do now
The immediate priority is confirming whether SMA1000 appliances are patched to the hotfix release SonicWall issued in mid-July, and if not, doing so without further delay. Because credentials and MFA seeds may already have been stolen in pre-disclosure attacks, patching alone is not sufficient — session tokens and MFA configurations should be rotated as a precaution.
Longer term, this incident is a useful case study for boards evaluating whether their current tooling and processes would catch this kind of chained exploitation. Building out effective vulnerability management programs, reviewing robust ransomware protection strategies, and making sure teams genuinely understand patch management best practices are all more valuable after an event like this than before it.
- •Confirm SMA1000 firmware is on the hotfix release issued in mid-July 2026
- •Audit internet-facing exposure of all SMA1000 6210, 7210 and 8200v units
- •Rotate VPN credentials, active sessions and TOTP MFA seeds as a precaution
- •Review MSSP and third-party access where SMA1000 sits in the supply chain
- •Escalate to incident response support if any indicators of compromise appear
- 01BleepingComputer — CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs · 10 August 2026
- 02The Hacker News — INC Ransomware emerges as dominant SonicWall SMA1000 exploiter · 8 August 2026
- 03Dark Reading — INC Ransomware exploits SonicWall SMA zero-days · 7 August 2026
- 04The Hacker News — Two SonicWall SMA1000 zero-days exploited before disclosure · 15 July 2026
- 05BleepingComputer — SonicWall SMA1000 flaws exploited as zero-days to push custom malware · 18 July 2026
