CVE Tools
Back to feed
Exploited in the wild SMA1000 Qilin ransomware SonicWall UTA0533

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has formally recognized that criminal groups are actively leveraging two critical vulnerabilities in SonicWall SMA1000 secure remote access gateways, specifically noting their use in ransomware campaigns. These flaws, identified as CVE-2026-15409 and CVE-2026-15410, include a high-severity SSRF issue and were originally patched by SonicWall in mid-July following warnings of zero-day exploitation. Following earlier reports that threat actor UTA0533 deployed custom malware like KNUCKLEBALL through these bugs since late June, CISA mandated federal agencies to apply fixes immediately, highlighting the significant risk posed to government infrastructure.