Exploited in the wild SMA1000 Qilin ransomware SonicWall UTA0533
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CVE Tools coverage
CISA has formally recognized that criminal groups are actively leveraging two critical vulnerabilities in SonicWall SMA1000 secure remote access gateways, specifically noting their use in ransomware campaigns. These flaws, identified as CVE-2026-15409 and CVE-2026-15410, include a high-severity SSRF issue and were originally patched by SonicWall in mid-July following warnings of zero-day exploitation. Following earlier reports that threat actor UTA0533 deployed custom malware like KNUCKLEBALL through these bugs since late June, CISA mandated federal agencies to apply fixes immediately, highlighting the significant risk posed to government infrastructure.