CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000
CISA confirmed ransomware operators are actively exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in unpatched SonicWall SMA1000 appliances. Patch has been available since July 14.
Ransomware operators have entered the SonicWall SMA1000 exploitation window. CISA confirmed August 10 that ransomware gangs are actively abusing CVE-2026-15409 — the unauthenticated server-side request forgery in the SMA1000 Work Place portal, CVSS 10.0 — alongside CVE-2026-15410, the post-authentication OS command injection. Source: BleepingComputer.
Patch has been available since July 14. If you’re running a vulnerable build today, that is a choice.
Timeline
- Before July 14 — Exploitation observed in the wild before public disclosure. Volexity later attributed early activity to UTA0533, a targeted intrusion actor operating with four custom post-exploitation implants.
- July 14 — SonicWall publishes SNWLID-2026-0008, fixed builds ship, CISA adds both CVEs to KEV, federal patch deadline set July 17.
- August 10 — CISA confirms ransomware operators now exploiting the same vulnerability pair. Source: BleepingComputer.
This is the predictable second phase. Nation-state or targeted actors get access first; ransomware operators follow once exploitation is established and tooling circulates. Specific ransomware group attribution: unconfirmed as of this writing.
Affected builds
SMA1000 models in scope: 6210, 7210, 8200v. Vulnerable builds: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, 12.5.0-02800.
Confirmed safe: 12.4.3-03453 and 12.5.0-02835 or later. SMA100 series is a separate product line — not in scope for this advisory.
If you haven’t patched
Treat an unpatched, internet-reachable SMA1000 as potentially compromised before patching — not vulnerable, compromised.
- Apply the patch now. Builds are available. This is not a scheduling question.
- Check the IoCs from SNWLID-2026-0008. The SonicWall advisory lists specific log paths and files —
extraweb_access.log,ctrl-service.log, and/var/lib/unit/conf.json. Malicious content in any of these means rebuild, not patch. - Rotate admin credentials. CVE-2026-15410 needs admin access to weaponize; if the SSRF was used to harvest session material, that credential may already be staged elsewhere.
- Audit user sessions on the Work Place portal. Out-of-window logins, unusual source ASNs, and unexpected internal target access are the signals worth pulling now.
Three weeks elapsed between the patch and this ransomware confirmation. Any unpatched SMA1000 that stayed internet-reachable through that window — investigate first, patch second.
Track all confirmed KEV vulnerabilities at our KEV tracker.
- [ CRITICAL ] CVE-2026-15409 SonicWall SMA1000 unauthenticated SSRF in Work Place portal
- [ HIGH ] CVE-2026-15410 SonicWall SMA1000 post-authentication OS command injection
Found this useful? Share it.


