CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. "SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," the company warned at the time. "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities." Incident response firm Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances. Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed online, although some may already have been secured against attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog ...
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
BleepingComputer
·Sergiu Gatlan
·Published Aug 10, 2026
·Updated
Affected Software
1 affected component
SonicWall SMA1000