CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA Confirms Ransomware Gangs Exploit SonicWall SMA1000 Flaws, Despite Patches

A critical vulnerability in SonicWall’s enterprise-grade secure remote access gateway, the SMA1000, has been confirmed to be actively exploited by ransomware gangs. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the vulnerabilities pose significant risks to the federal enterprise.

SonicWall’s SMA1000 is a popular choice among large corporations, government agencies, and Managed Service Providers (MSPs) for providing VPN access to internal applications and corporate networks. However, it appears that some of these organizations have not yet patched their systems, despite SonicWall’s warning in mid-July that the vulnerabilities were being exploited by threat actors.

According to incident response firm Volexity, a threat actor known as UTA0533 began exploiting the vulnerabilities as early as June 22, deploying custom malware on vulnerable VPN appliances. The malware included variants such as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL. With over 380 SMA1000 appliances exposed online, it’s likely that many organizations have not yet taken action to secure their systems.

The CISA warning is particularly concerning, given the agency’s role in protecting federal civilian executive branch (FCEB) agencies from cyber threats. The KEV Catalog is a critical resource for identifying vulnerabilities that are being actively exploited by threat actors. By adding these two flaws to the catalog, CISA is urging all organizations to take immediate action to patch their systems.

This incident highlights the importance of timely patching and vulnerability management. Despite SonicWall’s efforts to address the issue in mid-July, some organizations have yet to act. This delay has allowed threat actors to exploit the vulnerabilities, deploying malware that can compromise sensitive data. It’s a stark reminder that security teams must stay vigilant and proactive in defending against cyber threats.

For organizations still running unpatched SMA1000 systems, the risk of exploitation is very real. CISA recommends taking immediate action to patch systems and ensuring that all layers of security are properly configured. This includes not only patching software but also reviewing network configurations and monitoring for suspicious activity.

Ultimately, this incident serves as a reminder that cybersecurity is an ongoing process, requiring constant vigilance and attention to detail. By staying informed about emerging threats and taking proactive steps to secure systems, organizations can reduce the risk of exploitation and protect sensitive data from falling into the wrong hands.


Source: Bleeping Computer — 2026-08-10