CVE Tools
Back to feed
Exploited in the wild SMA1000 INC Ransomware ransomware SonicWall rce

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Two critical vulnerabilities in SonicWall's SMA1000 secure remote access appliances have been actively exploited in ransomware attacks, according to new research from Resecurity. The flaws—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—allow unauthenticated attackers to establish WebSocket tunnels and gain root-level access. These vulnerabilities were patched on July 14 and added to CISA’s KEV list, but were already being abused as zero-days since early June. The INC Ransomware group has emerged as the most active exploiter, targeting organizations globally and using aggressive tactics like phishing emails and fake support calls to pressure victims.