< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 8 sources · 30 days · First seen · Last updated

SonicWall SMA 1000 zero-day exploits

Overview

SonicWall Secure Mobile Access (SMA) 1000 series appliances have been targeted by active zero-day exploits. Initial reports identified two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which allow for remote code execution and unauthorized access. The cybercrime group INC Ransomware has been identified as a dominant actor using these flaws to exfiltrate data and deploy ransomware, employing a double-extortion model that includes direct pressure via phone calls and emails to victims across the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.

Subsequent technical details identified specific vulnerabilities affecting physical and virtual models 6210, 7210, and 8200v. These include CVE-2026-83548, a critical pre-authentication server-side request forgery (SSRF) with a CVSS rating of 10.0, and CVE-2026-83549, a post-authentication OS command injection vulnerability. Researchers noted that attackers may chain these vulnerabilities to achieve full device compromise. SonicWall has released hotfixes and advised compromised users to re-image appliances and reset administrative credentials.

Entities

SonicWall · INC Ransomware · William Perry · CISA · Resecurity

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 10 days ago

    [TECHNOLOGY] 8 sources
    SonicWall SMA 1000 appliances targeted by active zero-day exploits

    SonicWall is patching two actively exploited zero-day vulnerabilities in its SMA 1000 series appliances, including a critical CVSS 10.0 flaw that allows unauthenticated remote access.

  2. about 1 month ago

    [TECHNOLOGY] 10 sources
    INC Ransomware exploits SonicWall SMA 1000 zero‑days, pressures victims

    INC Ransomware exploits SonicWall SMA 1000 zero‑day flaws (CVE‑2026‑15409/15410) to breach networks, steal data and pressure victims with calls, affecting firms in the US, Australia, UAE and more.

Sources

csoonline.com.au · cybernoz.com · cyberscoop.com · esecurityplanet.com · it-boltwise.de · networkworld.com · securityaffairs.co · theregister.co.uk