Skip to main content

Tag: cve 2026 15410

6 articles

Rack-mounted networking equipment, including a remote-access gateway device, in a well-lit IT room with a blurred…

Ransomware gangs exploit SonicWall SMA1000 flaws

Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

Analyst 207
Network equipment racks with a SonicWall device in a well-lit office IT room.

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks

INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

Analyst 207
Rack-mounted SonicWall SMA1000 appliance in a network operations setting.

SonicWall VPN flaws exploited to install custom malware

A threat actor known as UTA0533 has been exploiting two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances to install custom malware, starting as early as June 22, 2026. This attack uses a critical server-side request forgery and a high-severity command injection vulnerability to gain unauthorized access.

Analyst 207
Rack-mounted SonicWall SMA1000 appliance in a typical office server closet.

Attackers Exploit Zero-Days in SonicWall Appliances

Cyber attackers are exploiting two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall appliances, with ransomware attacks seemingly their ultimate goal. Rapid7's team has thwarted attempts at data exfiltration and encryption, but the threat remains.

Analyst 207
Network equipment room with racked device, cables, and blurred management console.

SonicWall Zero-Days Exploited, Enable Admin Command Execution

SonicWall is urging immediate action to fix two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances, which are being actively exploited by attackers to execute admin-level commands. These critical flaws, tracked as CVE-2026-15409 and CVE-2026-15410, could compromise your system's security if not patched right away.

Analyst 207
Network equipment and security appliance in a secure facility setup.

SonicWall Disrupts Zero-Day Attacks with Urgent Patch for SMA1000 Flaws

SonicWall has issued a critical patch to combat zero-day attacks exploiting two vulnerabilities in its SMA1000 line, with attackers already taking advantage of these flaws in the wild. The company urges immediate action to prevent further damage from these actively exploited security gaps.

Analyst 207