Exploited in the wild SonicWall SMA 1000 INC Ransomware ransomware SonicWall zero-day
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
CVE Tools coverage
The INC Ransomware group has become the leading threat actor exploiting two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances—CVE-2026-15409 and CVE-2026-15410—which allow for arbitrary command execution and device compromise. These zero-day flaws were patched by SonicWall in mid-July 2026 but continue to be actively weaponized, enabling attackers to steal credentials and gain persistent access to networks. Resecurity reported a sharp increase in incidents since early August, with more than 800 victims globally. Organizations are urged to apply patches immediately and conduct thorough network assessments to prevent further breaches.