Skip to content
feed: live
>_ 0dayNews
sonicwall
● Breaking

CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000

CISA confirmed ransomware operators are actively exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in unpatched SonicWall SMA1000 appliances. Patch has been available since July 14.

airgap airgap · Published · 1 min read

Ransomware operators have entered the SonicWall SMA1000 exploitation window. CISA confirmed August 10 that ransomware gangs are actively abusing CVE-2026-15409 — the unauthenticated server-side request forgery in the SMA1000 Work Place portal, CVSS 10.0 — alongside CVE-2026-15410, the post-authentication OS command injection. Source: BleepingComputer.

Patch has been available since July 14. If you’re running a vulnerable build today, that is a choice.

Timeline

This is the predictable second phase. Nation-state or targeted actors get access first; ransomware operators follow once exploitation is established and tooling circulates. Specific ransomware group attribution: unconfirmed as of this writing.

Affected builds

SMA1000 models in scope: 6210, 7210, 8200v. Vulnerable builds: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, 12.5.0-02800.

Confirmed safe: 12.4.3-03453 and 12.5.0-02835 or later. SMA100 series is a separate product line — not in scope for this advisory.

If you haven’t patched

Treat an unpatched, internet-reachable SMA1000 as potentially compromised before patching — not vulnerable, compromised.

  1. Apply the patch now. Builds are available. This is not a scheduling question.
  2. Check the IoCs from SNWLID-2026-0008. The SonicWall advisory lists specific log paths and files — extraweb_access.log, ctrl-service.log, and /var/lib/unit/conf.json. Malicious content in any of these means rebuild, not patch.
  3. Rotate admin credentials. CVE-2026-15410 needs admin access to weaponize; if the SSRF was used to harvest session material, that credential may already be staged elsewhere.
  4. Audit user sessions on the Work Place portal. Out-of-window logins, unusual source ASNs, and unexpected internal target access are the signals worth pulling now.

Three weeks elapsed between the patch and this ransomware confirmation. Any unpatched SMA1000 that stayed internet-reachable through that window — investigate first, patch second.

Track all confirmed KEV vulnerabilities at our KEV tracker.

Related CVEs
  • [ CRITICAL ] CVE-2026-15409 SonicWall SMA1000 unauthenticated SSRF in Work Place portal
  • [ HIGH ] CVE-2026-15410 SonicWall SMA1000 post-authentication OS command injection

Found this useful? Share it.