SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation Wave
Summary
Hide ▲
Show ▼
SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root escalation used against exposed appliances. SonicWall patched the flaws on July 14, and CISA added both to KEV the same day after exploitation was confirmed. INC Ransomware has been the most active group in the wider campaign, while Volexity said UTA0533 began exploiting the flaws as early as June 22 to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
Related Happenings
INC Ransomware campaign expands across multiple victims
Campaign
H score43
First: 03.08.2026 13:39
Last: 03.08.2026 13:39
Sources 1
How related:
“Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS),” the company says.
About this happening:
The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...
INC Ransomware campaign expands across multiple victims
CampaignHow related: “Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS),” the company says.
About this happening: The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
How related:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionHow related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
Vulnerability
H score48
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
How related:
Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.
About this happening:
SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...
SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
VulnerabilityHow related: Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.
About this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...
Latest development: 03.08.2026 13:39
SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
UK healthcare cyber-attack surge accelerates in early 2026
Trend
H score71
First: 30.06.2026 12:30
Last: 30.06.2026 12:30
Sources 1
About this happening:
SonicWall detected a tenfold increase in attacks against the UK healthcare sector during January-May 2026, pushing pressure on hospital defenses and internet-facing ca...
UK healthcare cyber-attack surge accelerates in early 2026
TrendAbout this happening: SonicWall detected a tenfold increase in attacks against the UK healthcare sector during January-May 2026, pushing pressure on hospital defenses and internet-facing ca...
Timeline
-
03.08.2026 13:39 2 articles · 13d ago
SonicWall SMA1000 zero-days are exploited for remote access and root escalation
Exploitation ObservedAttackers abused CVE-2026-15409 and CVE-2026-15410 against SonicWall SMA1000 secure remote access appliances as zero-days by at least June 22, enabling unauthenticated access to restricted services and privilege escalation to root.
Show sources
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks — www.securityweek.com — 03.08.2026 13:39
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — www.bleepingcomputer.com — 10.08.2026 17:34
-
03.08.2026 13:39 1 articles · 13d ago
SonicWall patches CVE-2026-15409 and CVE-2026-15410
Mitigation Patch UpdateSonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, and CISA added both flaws to the Known Exploited Vulnerabilities catalog the same day after exploitation in the wild was confirmed.
Show sources
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks — www.securityweek.com — 03.08.2026 13:39
-
03.08.2026 13:39 2 articles · 13d ago
INC Ransomware expands SonicWall SMA1000 exploitation across multiple victims
Initial DisclosureBy August 2026, INC Ransomware had become the most active group chaining the SonicWall flaws, with multiple new victims from the US, Australia, UAE, Colombia, and Switzerland appearing on its leak site and some victims receiving follow-up emails and phone calls claiming to help with ransomware issues.
Show sources
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks — www.securityweek.com — 03.08.2026 13:39
- Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks — www.securityweek.com — 03.08.2026 13:39