Critical SonicWall Vulnerabilities Exploited in Ransomware Attacks
Recent SonicWall vulnerabilities are being exploited by ransomware groups, prompting urgent security advisories.
Introduction
The INC Ransomware group has been identified as the primary actor leveraging two newly disclosed vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, according to Resecurity. The flaws, designated CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), enable unauthenticated remote adversaries to establish a WebSocket connection to restricted services and escalate privileges to root.
Vulnerabilities Details
These issues were addressed on July 14 and subsequently included in CISA’s Known Exploited Vulnerabilities (KEV) list on the same day. However, threat actors had already begun exploiting the flaws as zero-days starting at least June 22. Volexity linked the exploitation of these vulnerabilities to a threat actor tracked as UTA0533, which was observed extracting credentials from compromised devices and deploying malicious payloads.
Threat Actor Analysis
However, this group faced challenges in extending its access to additional systems. In contrast, Rapid7 reported that adversaries leveraged compromised SMA1000 appliances to infiltrate internal corporate networks, likely by deploying backdoors on the affected devices.
Ransomware Group Activities
Resecurity highlighted that among the various threat actors exploiting the vulnerabilities, the INC Ransomware gang has demonstrated the highest level of activity. The group accelerated its operations in early August 2026, with multiple new victims disclosed on its Data Leak Site (DLS). Over the past weeks, the ransomware collective has targeted organizations across the private and public sectors in the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.
Victim Tactics
Resecurity noted that victims of the INC Ransomware group have received unsolicited communications, including emails and phone calls from entities posing as cybersecurity assistance providers. One instance involved a domain associated with these outreach efforts, while another involved a caller identifying as Andrew, claiming to represent a hacking collective. The individual provided an email address, info@helprans[.]com, for further negotiations before ending the call.
Security Advice
Security experts advise users of SonicWall SMA1000 appliances to apply the available patches immediately and conduct thorough threat hunting to detect potential compromises. The ongoing exploitation of these vulnerabilities underscores the critical need for timely mitigation and proactive security measures.
