sonicwall

CVE-2026-15409critical
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

ransomwarecritical
Inc Ransomware Exploits SonicWall SMA Zero-Days
The Inc ransomware group is actively exploiting two zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances. Successful exploitation grants attackers root-level control over the affected devices, enabling further malicious activities.