Find notable cyber news and cases, enriched with sources, timelines, and signals.

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave
First reported
Last updated
Happening score
H score 57
1 unique sources, 1 articles

Summary

Hide ▲

Attackers are conducting an active zero-day exploitation wave against SonicWall SMA1000 appliances using CVE-2026-15409 and CVE-2026-15410, creating takeover risk for exposed remote-access systems. The flaws let unauthenticated attackers open a WebSocket tunnel to restricted services and escalate to root, which can turn edge appliances into launch points for internal network access. The activity has been underway since at least June 22 and has already produced multiple new victims across several regions and sectors.

Related Happenings

INC Ransomware campaign expands across multiple victims

Campaign
H score43 First: 03.08.2026 13:39 Last: 03.08.2026 13:39 Sources 1

How related: “Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS),” the company says.

About this happening: The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...

SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)

Vulnerability
H score48 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

How related: Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.

About this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against SMA1000 Secure Mobile Access appliances, with SonicWall...

Latest development: 03.08.2026 13:39

SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.

UK healthcare cyber-attack surge accelerates in early 2026

Trend
H score71 First: 30.06.2026 12:30 Last: 30.06.2026 12:30 Sources 1

About this happening: SonicWall detected a tenfold increase in attacks against the UK healthcare sector during January-May 2026, pushing pressure on hospital defenses and internet-facing ca...

PAN-OS GlobalProtect CVE-2026-0257 exploitation wave

Exploitation Wave
H score18 First: 01.06.2026 11:30 Last: 01.06.2026 11:30 Sources 1

About this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....

SonicWall Gen6 SSL-VPN MFA-bypass flaw (CVE-2024-12802)

Vulnerability
H score50 First: 21.05.2026 00:19 Last: 21.05.2026 00:19 Sources 1

About this happening: Researchers confirmed first-in-the-wild exploitation of CVE-2024-12802 against SonicWall Gen6 SSL-VPN appliances, showing that incomplete remediation can leave MFA b...

Timeline

  1. 03.08.2026 13:39 1 articles · 1h ago

    SonicWall SMA1000 zero-days are exploited for remote access and root escalation

    Exploitation Observed

    Attackers abused CVE-2026-15409 and CVE-2026-15410 against SonicWall SMA1000 secure remote access appliances as zero-days by at least June 22, enabling unauthenticated access to restricted services and privilege escalation to root.

    Show sources
  2. 03.08.2026 13:39 1 articles · 1h ago

    SonicWall patches CVE-2026-15409 and CVE-2026-15410

    Mitigation Patch Update

    SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, and CISA added both flaws to the Known Exploited Vulnerabilities catalog the same day after exploitation in the wild was confirmed.

    Show sources
  3. 03.08.2026 13:39 2 articles · 1h ago

    INC Ransomware expands SonicWall SMA1000 exploitation across multiple victims

    Initial Disclosure

    By August 2026, INC Ransomware had become the most active group chaining the SonicWall flaws, with multiple new victims from the US, Australia, UAE, Colombia, and Switzerland appearing on its leak site and some victims receiving follow-up emails and phone calls claiming to help with ransomware issues.

    Show sources