Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

https://www.securityweek.com/wp-content/uploads/2025/08/SonicWall.jpg

The INC Ransomware group is responsible for most of the recent activity surrounding two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, Resecurity reports.

Tracked as CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), the security defects allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and escalate their privileges to root.

Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.

Cybersecurity firm Volexity attributed the observed exploitation to a threat actor tracked as UTA0533, noting that it was harvesting credentials from the hacked appliances and deploying malicious files, but was less successful in moving laterally to other systems.

Rapid7, on the other hand, observedthreat actors pivoting from SMA1000 devices into internal corporate networks, likely after deploying...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more