CVE Tools

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

BleepingComputerBy Sergiu Gatlan

Reported exploitedSMA1000Qilin

Our summary

CISA has formally recognized that criminal groups are actively leveraging two critical vulnerabilities in SonicWall SMA1000 secure remote access gateways, specifically noting their use in ransomware campaigns. These flaws, identified as CVE-2026-15409 and CVE-2026-15410, include a high-severity SSRF issue and were originally patched by SonicWall in mid-July following warnings of zero-day exploitation. Following earlier reports that threat actor UTA0533 deployed custom malware like KNUCKLEBALL through these bugs since late June, CISA mandated federal agencies to apply fixes immediately, highlighting the significant risk posed to government infrastructure.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store