Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 8 sources · 30 days · First seen · Last updated
SonicWall SMA 1000 zero-day exploits
Overview
SonicWall Secure Mobile Access (SMA) 1000 series appliances have been targeted by active zero-day exploits. Initial reports identified two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which allow for remote code execution and unauthorized access. The cybercrime group INC Ransomware has been identified as a dominant actor using these flaws to exfiltrate data and deploy ransomware, employing a double-extortion model that includes direct pressure via phone calls and emails to victims across the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.
Subsequent technical details identified specific vulnerabilities affecting physical and virtual models 6210, 7210, and 8200v. These include CVE-2026-83548, a critical pre-authentication server-side request forgery (SSRF) with a CVSS rating of 10.0, and CVE-2026-83549, a post-authentication OS command injection vulnerability. Researchers noted that attackers may chain these vulnerabilities to achieve full device compromise. SonicWall has released hotfixes and advised compromised users to re-image appliances and reset administrative credentials.
Entities
SonicWall · INC Ransomware · William Perry · CISA · Resecurity
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] SonicWall confirmed that two zero-day vulnerabilities in its SMA 1000 series appliances are being actively exploited. www.csoonline.com · cybernoz.com · www.it-boltwise.de · securityaffairs.com · www.networkworld.com · +1 more
- [● 6 SOURCES] CVE-2026-83548 is a pre-authentication SSRF vulnerability with a CVSS severity rating of 10.0. www.csoonline.com · cybernoz.com · www.it-boltwise.de · securityaffairs.com · www.networkworld.com · +1 more
- [● 6 SOURCES] CVE-2026-83549 is a post-authentication OS command injection vulnerability with a CVSS severity rating of 7.8. www.csoonline.com · cybernoz.com · www.it-boltwise.de · securityaffairs.com · www.networkworld.com · +1 more
- [● 4 SOURCES] Compromised customers are advised to re-image appliances, change all passwords, and reset TOTP tokens. www.csoonline.com · cybernoz.com · securityaffairs.com · www.theregister.com
- [● 3 SOURCES] The vulnerabilities affect SMA 1000 models 6210, 7210, and 8200v. cybernoz.com · securityaffairs.com · www.theregister.com
- [● 3 SOURCES] SonicWall has released hotfixes to address the vulnerabilities. cybernoz.com · securityaffairs.com · www.theregister.com
- [● 2 SOURCES] Attackers may be chaining the two flaws to achieve remote code execution. securityaffairs.com · www.theregister.com
Timeline
-
10 days ago
[TECHNOLOGY] 8 sourcesSonicWall SMA 1000 appliances targeted by active zero-day exploitsSonicWall is patching two actively exploited zero-day vulnerabilities in its SMA 1000 series appliances, including a critical CVSS 10.0 flaw that allows unauthenticated remote access.
-
about 1 month ago
[TECHNOLOGY] 10 sourcesINC Ransomware exploits SonicWall SMA 1000 zero‑days, pressures victimsINC Ransomware exploits SonicWall SMA 1000 zero‑day flaws (CVE‑2026‑15409/15410) to breach networks, steal data and pressure victims with calls, affecting firms in the US, Australia, UAE and more.
Sources
csoonline.com.au · cybernoz.com · cyberscoop.com · esecurityplanet.com · it-boltwise.de · networkworld.com · securityaffairs.co · theregister.co.uk