CISA has confirmed that ransomware gangs are exploiting two recently patched SonicWall SMA1000 flaws.

The vulnerabilities affect enterprise VPN gateways used by large organisations, government agencies and managed service providers. Administrators should apply the available hotfixes immediately.

One of the issues is a maximum-severity server-side request forgery flaw. Both bugs had already been exploited as zero-days before SonicWall disclosed them.

Two flaws linked to ransomware attacks

The affected vulnerabilities are tracked as CVE-2026-15409 and CVE-2026-15410. SonicWall released patches for both flaws in mid-July.

At the time, the company warned that attackers were actively exploiting the issues. It urged customers to upgrade to the hotfix release as soon as possible.

CISA added both SonicWall SMA1000 flaws to its Known Exploited Vulnerabilities catalog on July 14. Federal civilian agencies had three days to patch affected systems.

Recent KEV catalog updates now identify both flaws as exploited by ransomware gangs. This raises the risk for any organisation that has delayed patching.

Attackers used zero-days before disclosure

Incident response firm Volexity said a threat actor known as UTA0533 started exploiting the flaws on June 22.

The attacks began weeks before SonicWall publicly disclosed the vulnerabilities. The group used compromised SMA1000 appliances to deploy custom malware.

Researchers identified several malware families in those attacks. They include KNUCKLEBALL, Sou5, ROOTRUN and ORANGETAIL.

These tools may give attackers a foothold inside a network. From there, they can steal data, deploy further payloads or prepare ransomware attacks.

Hundreds of appliances remain exposed

Shadowserver tracks more than 380 SonicWall SMA1000 appliances exposed online. Some of these systems may already be patched or otherwise secured.

However, every exposed and unpatched appliance is a potential entry point. Organisations should identify all SMA1000 devices and check their patch status.

Security teams should also review logs for unusual activity. Suspicious remote access attempts, configuration changes and new administrator accounts can indicate compromise.

SonicWall users face continuing risk

SonicWall has dealt with several serious security issues in recent months.

In December, the company warned about another SMA1000 zero-day. Attackers chained that flaw to gain root privileges on Appliance Management Console systems.

SonicWall also linked state-backed hackers to a September breach. That incident exposed customer firewall configuration backup files.

The company later released firmware to remove OVERSTEP rootkit malware. Attackers had deployed the malware against SonicWall SMA 100 series devices.

The latest warning makes fast patching essential. Organisations should treat the SonicWall SMA1000 flaws as an urgent ransomware risk.


0 responses to “CISA Says SonicWall SMA1000 Flaws Are Exploited by Ransomware Gangs”