Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

Published August 3, 2026

Attackers are breaking into SonicWall SMA1000 remote access appliances without needing a password, then taking full control as root. A ransomware gang called INC is now the most active group using this to break into companies and list them on its leak site.

Report priority
High
Involves
SonicWall
Group
Recent SonicWall Vulnerabilities Exploited in

What is known

An attacker opens a WebSocket connection to a part of the SMA1000 that is supposed to be off limits, and that connection lets them reach restricted internal services and then escalate their own access up to root, the highest level of control on the device.

What to do

Check whether your organization's SMA1000 appliance is running a build from before the July 14, 2026 patch, and review SonicWall's advisory for the exact fixed firmware version and build number for your model.

Apply SonicWall's July 14, 2026 patch for CVE-2026-15409 and CVE-2026-15410 immediately, then have your security team hunt for signs of prior compromise such as unexpected credential use or unfamiliar files on the appliance, since these flaws were exploited as zero-days since at least June 22.

Reported details

An attacker finds an internet-exposed SonicWall SMA1000 appliance and opens a WebSocket tunnel to it without logging in. That tunnel reaches restricted internal services, letting the attacker escalate to root and harvest credentials stored on the device. With root access and stolen logins, the INC ransomware gang pivots into the company's internal network and later lists the victim on its leak site.

CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2) let an unauthenticated remote attacker open a WebSocket tunnel to restricted services on SonicWall SMA1000 appliances and escalate privileges to root. Volexity attributes early exploitation to UTA0533, which harvested credentials and dropped files but had limited lateral movement success. Rapid7 observed other actors pivoting from compromised appliances into internal networks, likely via a backdoor.

Both flaws were patched July 14, 2026 and added to CISA's KEV catalog the same day, but had been exploited since at least June 22. INC Ransomware has since become the most active group chaining both CVEs for initial access.