"SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," SonicWall warned — a concise acknowledgment that a pair of recently patched flaws in the SMA1000 remote-access gateway are now being weaponized in the wild.
CVE-2026-15409 and CVE-2026-15410: patches and an SSRF rated maximum-severity
SonicWall released hotfixes for two SMA1000 vulnerabilities in mid July, tracked as CVE-2026-15409 and CVE-2026-15410. One of the flaws is described as a maximum-severity server-side request forgery (SSRF), a class of bug that can let remote attackers coerce a vulnerable server to send requests on their behalf. SonicWall warned customers at the time that threat actors had been exploiting the flaws in zero-day attacks and "customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities."
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) moved quickly: it added both CVEs to its Known Exploited Vulnerabilities (KEV) Catalog on July 14 and ordered Federal Civilian Executive Branch (FCEB) agencies to patch affected systems within three days. As CISA put it, "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."
Evidence of real-world exploitation and malware families observed
Independent investigators documented exploitation that preceded public disclosure. Incident response firm Volexity reported that a threat actor tracked as UTA0533 began exploiting the SMA1000 flaws as early as June 22 — several weeks before SonicWall's mid-July advisory. According to Volexity, UTA0533 used the vulnerabilities to deploy custom malware families identified as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on compromised VPN appliances.
While SonicWall's advisory has not been updated to explicitly confirm that CVE-2026-15409 and CVE-2026-15410 were used in ransomware attacks, CISA's KEV entries have been updated to flag the two flaws as exploited by ransomware gangs in recent updates to that catalog.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSMA1000 footprint and prior SMA security incidents
The SMA1000 is positioned as an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks — making vulnerabilities in it particularly consequential. Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed to the public internet, although Shadowserver notes some of those may already have been secured.
The two July CVEs are not the first SMA1000 vulnerabilities to draw active exploitation. In December, SonicWall warned customers to patch CVE-2025-40602 in the SMA1000 Appliance Management Console that was being chained by attackers in zero-day campaigns to gain root privileges. One month earlier, SonicWall publicly linked state-sponsored hackers to a September security breach that exposed customers' firewall configuration backup files after researchers reported more than 100 SonicWall SSLVPN accounts had been compromised using stolen credentials. In September, SonicWall pushed a firmware update intended to help remove OVERSTEP rootkit malware deployed against SMA 100 series devices.
What this means for technologists, FCEB agencies, and MSSPs
- Technologists and security teams: SonicWall explicitly advised upgrading to the hotfix release; Volexity's timeline shows exploitation began before public disclosure, reinforcing urgency to apply patches and validate appliance integrity where possible.
- Federal Civilian Executive Branch (FCEB) agencies: CISA's July 14 KEV listing imposed a three-day remediation requirement — a short window that converts advisory language into an operational compliance mandate for affected federal entities.
- Managed Service Providers (MSSPs) and affected enterprises: with Shadowserver tracking over 380 exposed SMA1000 appliances, service providers must inventory externally reachable appliances and confirm whether hotfixes and any necessary incident response steps have been completed.
Detection gaps and operational realities
The record here illustrates two repeated operational themes: vulnerabilities in widely deployed remote-access gateways are high-value targets, and many intrusions can proceed before public disclosure. A banner in the reporting cited security telemetry that "Security teams log 54% of successful attacks and alert on just 14%," underscoring that detection and alerting shortfalls can allow exploitation to persist even after fixes are available.
For organizations that use SMA1000 appliances, the factual sequence is straightforward: (1) exploit activity was observed by at least one incident response firm beginning June 22; (2) SonicWall published hotfixes in mid July and urged immediate upgrading; (3) CISA placed the CVEs on its KEV Catalog on July 14, invoking a three-day patch requirement for FCEB agencies; and (4) CISA has since flagged the flaws as used by ransomware gangs. SonicWall has not, to date, revised its original advisory to state explicitly that these CVEs were used in ransomware attacks, leaving a narrow but concrete gap between vendor advisories and federal cataloging.
What remains clear from the public record is that exposed SMA1000 appliances have attracted active exploitation, tailored malware families have been deployed on compromised devices, and both vendors and federal authorities have pressed for rapid remediation. How quickly exposed systems are discovered and patched will determine whether these particular vulnerabilities continue to serve as an avenue for further intrusion.
Original reporting: CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — BleepingComputer




