Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
Reported exploitedSMA1000INC RansomwareOur summary
Two critical vulnerabilities in SonicWall's SMA1000 secure remote access appliances have been actively exploited in ransomware attacks, according to new research from Resecurity. The flaws—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—allow unauthenticated attackers to establish WebSocket tunnels and gain root-level access. These vulnerabilities were patched on July 14 and added to CISA’s KEV list, but were already being abused as zero-days since early June. The INC Ransomware group has emerged as the most active exploiter, targeting organizations globally and using aggressive tactics like phishing emails and fake support calls to pressure victims.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.