A Major Ransomware Group Exploits Critical Vulnerabilities in SonicWall Appliances
In a disturbing development, hackers from the notorious Inc ransomware-as-a-service group have been exploiting two zero-day vulnerabilities in SonicWall’s Secure Mobile Access (SMA) appliances. The security flaws, CVE-2026-15409 and CVE-2026-15410, allow attackers to gain root-level access to these devices, putting millions of users at risk.
The two vulnerabilities, discovered by Rapid7, a leading cybersecurity firm, can be exploited independently, but their true power lies in combination. When chained together, they enable unauthenticated attackers to execute remote code and run commands on the SMA appliances at the operating system level. This is particularly concerning because SonicWall’s SMA 1000 Series devices are used as gateways between external networks and internal systems, making them a prime target for hackers.
According to Rapid7, threat actors have been using CVE-2026-15409, a server-side request forgery (SSRF) issue in the SMA’s “Work Place” Web interface, to gain remote code execution capabilities. This vulnerability is particularly concerning because it requires no authentication and has earned a maximum 10 out of 10 score in the Common Vulnerability Scoring System (CVSS). The second vulnerability, CVE-2026-15410, earned a lesser but still high 7.2 out of 10 CVSS score, as it requires an attacker to already have access to the Appliance Management Console (AMC).
The exploitation of these vulnerabilities has been linked to the Inc ransomware group, which is known for its aggressive tactics and high-profile attacks. According to Rapid7’s telemetry data, hackers are using these vulnerabilities to establish a foothold in enterprise networks, stealing credentials, active session databases, and one-time login codes. They then use this access to perform lateral movement across corporate networks, targeting domain controllers.
The exploitation of these vulnerabilities highlights the importance of patching and regular security updates. SonicWall has released a security advisory regarding the two flaws, but many organizations may still be running outdated software. It is crucial for IT teams to prioritize patching and ensure that all systems are up-to-date with the latest security patches.
In practical terms, this means that users should take immediate action to address these vulnerabilities. This includes applying the latest security patches, reviewing logs for suspicious activity, and implementing additional security measures such as intrusion detection and prevention systems (IDPS). By taking proactive steps, organizations can reduce their exposure to these types of attacks and protect themselves from the devastating consequences of a ransomware attack.
Source: Dark Reading — 2026-07-17