Find notable cyber news and cases, enriched with sources, timelines, and signals.

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave
First reported
Last updated
Happening score
H score 24
2 unique sources, 2 articles

Summary

Hide ▲

SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root escalation used against exposed appliances. SonicWall patched the flaws on July 14, and CISA added both to KEV the same day after exploitation was confirmed. INC Ransomware has been the most active group in the wider campaign, while Volexity said UTA0533 began exploiting the flaws as early as June 22 to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.

Related Happenings

INC Ransomware campaign expands across multiple victims

Campaign
H score43 First: 03.08.2026 13:39 Last: 03.08.2026 13:39 Sources 1

How related: “Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS),” the company says.

About this happening: The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

How related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...

SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)

Vulnerability
H score48 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

How related: Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.

About this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...

Latest development: 03.08.2026 13:39

SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.

SonicWall security patch release for CVE-2026-15409

Security Patch Release
H score54 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

About this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...

UK healthcare cyber-attack surge accelerates in early 2026

Trend
H score71 First: 30.06.2026 12:30 Last: 30.06.2026 12:30 Sources 1

About this happening: SonicWall detected a tenfold increase in attacks against the UK healthcare sector during January-May 2026, pushing pressure on hospital defenses and internet-facing ca...

Timeline

  1. 03.08.2026 13:39 2 articles · 13d ago

    SonicWall SMA1000 zero-days are exploited for remote access and root escalation

    Exploitation Observed

    Attackers abused CVE-2026-15409 and CVE-2026-15410 against SonicWall SMA1000 secure remote access appliances as zero-days by at least June 22, enabling unauthenticated access to restricted services and privilege escalation to root.

    Show sources
  2. 03.08.2026 13:39 1 articles · 13d ago

    SonicWall patches CVE-2026-15409 and CVE-2026-15410

    Mitigation Patch Update

    SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, and CISA added both flaws to the Known Exploited Vulnerabilities catalog the same day after exploitation in the wild was confirmed.

    Show sources
  3. 03.08.2026 13:39 2 articles · 13d ago

    INC Ransomware expands SonicWall SMA1000 exploitation across multiple victims

    Initial Disclosure

    By August 2026, INC Ransomware had become the most active group chaining the SonicWall flaws, with multiple new victims from the US, Australia, UAE, Colombia, and Switzerland appearing on its leak site and some victims receiving follow-up emails and phone calls claiming to help with ransomware issues.

    Show sources