sonicwallcritical
Ransomware Gangs Exploit SonicWall SMA1000 Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting two vulnerabilities in SonicWall's SMA1000 series appliances. These flaws, which have already been patched, include a critical server-side request forgery (SSRF) vulnerability. The exploitation is linked to ransomware attacks.
CVE-2026-15409critical
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.