CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

A pair of critical vulnerabilities in SonicWall’s SMA1000 secure remote access gateway has been exploited by ransomware gangs, leaving countless organizations at risk. The flaws, which were patched by SonicWall in mid-July, have already been targeted in zero-day attacks, with threat actors deploying custom malware on vulnerable VPN appliances.

The affected vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, are a maximum-severity server-side request forgery (SSRF) flaw and another related issue. These types of flaws allow attackers to trick the system into making unauthorized requests on behalf of the victim, potentially leading to data breaches or even complete system takeover.

SonicWall’s SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. It’s alarming that these vulnerabilities have been exploited in real-world attacks, especially considering that SonicWall had already warned customers of the potential risks in mid-July.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days. However, with over 380 SMA1000 appliances exposed online, as tracked by internet security watchdog Shadowserver, it’s likely that many organizations are still at risk.

Ransomware gangs have been known to exploit vulnerabilities like these to deploy custom malware on compromised devices. In this case, the attackers appear to be using malware such as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL to gain access to sensitive systems. It’s essential for organizations using SonicWall SMA1000 to take immediate action to patch their systems and prevent potential breaches.

This incident highlights the importance of timely vulnerability patching and regular security updates. Organizations must prioritize testing and deploying patches as soon as they become available, rather than waiting for an attack to occur. By doing so, they can significantly reduce the risk of a breach and protect sensitive data from falling into the wrong hands.

In light of this incident, it’s crucial for organizations to review their vulnerability management processes and ensure that all systems are up-to-date with the latest patches. Additionally, regular security testing and monitoring can help detect potential threats before they escalate into full-blown attacks. By taking proactive steps towards securing their networks, organizations can minimize the risk of a ransomware attack and protect themselves from the devastating consequences that come with it.


Source: Bleeping Computer — 2026-08-10