CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. "SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," the company warned at the time. "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities." Incident response firm Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances. Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed online, although some may already have been secured against attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog ...
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
BleepingComputer
·Sergiu Gatlan
·Published Aug 10, 2026
·Updated
Affected Software
1 affected component
SonicWall SMA1000
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of vulnerabilities in the SonicWall SMA1000 by ransomware gangs.
2
What security implications are discussed in the article?
The article highlights the risk posed by a maximum-severity server-side request forgery (SSRF) vulnerability in the SonicWall SMA1000.
3
Who is affected by the SonicWall SMA1000 vulnerabilities?
Large corporations and government agencies using the SonicWall SMA1000 secure remote access gateway are affected.
4
What are the specific vulnerabilities that are being exploited?
The article mentions two recently patched vulnerabilities, including a server-side request forgery (SSRF) flaw, that are now being exploited.
5
When were these vulnerabilities reported and confirmed as exploited?
The vulnerabilities were published on August 10, 2026, and confirmed as exploited by ransomware gangs shortly thereafter.