CVE Tools

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

SecurityWeekBy Ionut Arghire

Reported exploitedSMA1000INC Ransomware

Our summary

Two critical vulnerabilities in SonicWall's SMA1000 secure remote access appliances have been actively exploited in ransomware attacks, according to new research from Resecurity. The flaws—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—allow unauthenticated attackers to establish WebSocket tunnels and gain root-level access. These vulnerabilities were patched on July 14 and added to CISA’s KEV list, but were already being abused as zero-days since early June. The INC Ransomware group has emerged as the most active exploiter, targeting organizations globally and using aggressive tactics like phishing emails and fake support calls to pressure victims.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store