Cybersecurity experts are sounding the alarm after a major ransomware group exploited two previously unknown vulnerabilities in SonicWall’s Secure Mobile Access (SMA) appliances. The zero-day attacks have already compromised multiple enterprise networks, highlighting the critical need for prompt action to secure these devices.
The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, allow attackers to gain root-level access on SMA 1000 Series appliances. According to SonicWall’s security advisory, CVE-2026-15409 is a server-side request forgery (SSRF) issue in the SMA’s “Work Place” Web interface, which enables unauthenticated attackers to craft malicious requests that trick the portal into accessing internal services. This vulnerability has earned a maximum 10 out of 10 score in the Common Vulnerability Scoring System (CVSS). CVE-2026-15410 is a code injection flaw that requires an attacker to already have access to the Appliance Management Console (AMC), but can still execute arbitrary operating system-level commands.
Rapid7, a cybersecurity firm, has reported that threat actors connected to the infamous Inc ransomware-as-a-service group are exploiting these vulnerabilities as zero-days. The attacks involve using CVE-2026-15409 to gain code execution and then pivoting to CVE-2026-15410 to escalate privileges from an unauthenticated outsider to a root-level insider. Rapid7 has published a proof-of-concept exploit for the former vulnerability on GitHub.
The connection between these vulnerabilities and Inc ransomware is concerning, as it highlights the potential for widespread compromise. The Cybersecurity and Infrastructure Security Agency (CISA) has added both CVEs to its Known Exploited Vulnerabilities catalog. Rapid7’s telemetry data shows that attackers are using these vulnerabilities to gain access to enterprise networks, steal credentials, and perform lateral movement across corporate systems.
The true extent of the damage is still unknown, but experts warn that compromising an edge device like a SonicWall SMA 1000 Series appliance is often just the first step in a larger attack. Brett Deroche, director of incident response at Rapid7, notes that “the ultimate objective remains exactly what it has always been: monetization.” In this case, the attackers are likely seeking to deploy ransomware and extort victims.
In light of these findings, organizations using SonicWall SMA 1000 Series appliances should take immediate action to secure their devices. This includes applying any available patches or updates, reviewing access controls, and monitoring for suspicious activity. As experts remind us, preventing a breach is often more effective than responding to one after it happens.
Source: Dark Reading — 2026-07-17