Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
A sophisticated ransomware gang has been exploiting two newly discovered vulnerabilities in SonicWall’s SMA1000 secure remote access appliances. The INC Ransomware group has been targeting organizations across the globe, including government and private sector entities in the US, Australia, UAE, Colombia, and Switzerland. The attack chain involves unauthenticated remote attackers using the vulnerabilities to gain root privileges on compromised devices.
The two vulnerabilities, tracked as CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), were patched by SonicWall on July 14th and added to the CISA’s Known Exploited Vulnerabilities (KEV) catalog the same day. However, threat actors had been exploiting these flaws as zero-days since at least June 22nd. Cybersecurity firm Volexity attributed the observed exploitation to a threat actor tracked as UTA0533, which was harvesting credentials from hacked appliances and deploying malicious files.
The INC Ransomware gang has emerged as the most active group exploiting these vulnerabilities, with multiple new victims listed on their Data Leak Site (DLS) in August. The affected organizations received emails and phone calls from unknown individuals claiming to assist with ransomware issues, which is a common tactic used by ransomware groups to pressure victims into paying the ransom.
The attack chain begins when an unauthenticated remote attacker uses the CVE-2026-15409 vulnerability to open a WebSocket tunnel to restricted services on the compromised device. This allows the attacker to escalate their privileges to root and deploy malicious files, which can be used for lateral movement into other systems. Threat actors have been observed pivoting from SMA1000 devices into internal corporate networks, likely after deploying a backdoor on the compromised appliances.
As ransomware groups continue to target these vulnerabilities, it is essential for users to patch their SMA1000 appliances as soon as possible and perform threat hunting to identify potential compromises. Resecurity recommends that organizations take immediate action to secure their systems, including conducting vulnerability assessments and implementing additional security measures to prevent further exploitation.
The recent attacks highlight the importance of staying up-to-date with patches and maintaining robust cybersecurity defenses. Organizations should prioritize patching their SonicWall appliances and consider conducting regular threat hunting exercises to identify potential compromises. By taking proactive steps to address these vulnerabilities, organizations can reduce the risk of falling victim to these types of attacks.
Source: SecurityWeek — 2026-08-03