Tag: cve 2026 15409
6 articles

Ransomware gangs exploit SonicWall SMA1000 flaws
Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks
INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

SonicWall VPN flaws exploited to install custom malware
A threat actor known as UTA0533 has been exploiting two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances to install custom malware, starting as early as June 22, 2026. This attack uses a critical server-side request forgery and a high-severity command injection vulnerability to gain unauthorized access.

Attackers Exploit Zero-Days in SonicWall Appliances
Cyber attackers are exploiting two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall appliances, with ransomware attacks seemingly their ultimate goal. Rapid7's team has thwarted attempts at data exfiltration and encryption, but the threat remains.

SonicWall Zero-Days Exploited, Enable Admin Command Execution
SonicWall is urging immediate action to fix two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances, which are being actively exploited by attackers to execute admin-level commands. These critical flaws, tracked as CVE-2026-15409 and CVE-2026-15410, could compromise your system's security if not patched right away.

SonicWall Disrupts Zero-Day Attacks with Urgent Patch for SMA1000 Flaws
SonicWall has issued a critical patch to combat zero-day attacks exploiting two vulnerabilities in its SMA1000 line, with attackers already taking advantage of these flaws in the wild. The company urges immediate action to prevent further damage from these actively exploited security gaps.