ALITEQ.

a ransomware crew had root on SonicWall's boxes for weeks before anyone noticed

CVE-2026-15409 and CVE-2026-15410 let INC ransomware walk into SMA 1000 appliances as root — SonicWall didn't even know the holes existed until the attacks were already underway.

Ravi MalhotraUpdated 50m ago6 min readWeb story
A rack-mounted network security appliance similar to SonicWall's SMA 1000 series sitting at the edge of a company network

SonicWall published a security advisory on July 14, 2026 for two flaws in its SMA 1000 Series appliances — the boxes a lot of mid-size companies use for secure remote access. Routine enough, except for one detail: a threat actor had already been using both bugs since June 22, three weeks before SonicWall knew they existed. CVE-2026-15409 and CVE-2026-15410, chained together, let an attacker with no valid credentials tunnel into a company's internal network and run commands as root. If you run an SMA 1000 and haven't patched to 12.4.3-03453 or 12.5.0-02835 yet, this is the one to stop and do today.

How CVE-2026-15409 and CVE-2026-15410 work together

The two bugs aren't dangerous in isolation so much as in sequence. CVE-2026-15409 is a server-side request forgery flaw that lets an attacker open a tunnel from the open internet into services that were only ever meant to be reachable internally. Once inside, CVE-2026-15410 — a code-injection flaw — lets that same attacker run arbitrary operating-system commands. Chain the two together and you get unauthenticated remote code execution as root, on an appliance whose entire job is being the secure gateway into the network.

The two CVEs

CVE-2026-15409

CVSS
10.0
Type
Server-side request forgery
What it lets an attacker do
Open a tunnel from the open internet into internal-only services

CVE-2026-15410

CVSS
7.2
Type
Code injection
What it lets an attacker do
Run arbitrary OS commands once inside

How this played out

  1. June 22, 2026

    Volexity later determines a threat cluster it tracks begins exploiting both flaws as zero-days — weeks before any patch or public advisory existed.

  2. July 14, 2026

    SonicWall publishes its advisory for CVE-2026-15409 and CVE-2026-15410, more than three weeks after exploitation began.

  3. Days later

    A threat actor connected to the INC ransomware-as-a-service operation starts using the same exploit chain against newly disclosed targets, per Rapid7 telemetry.

  4. Through August 2026

    SonicWall's guidance goes beyond patching: re-image affected appliances, rotate every admin and user password, and reset TOTP tokens — the kind of response reserved for boxes that may already be compromised.

A rack-mounted network security appliance similar to SonicWall's SMA 1000 series
SMA 1000 appliances sit at the edge of a company's network by design — exactly why root access on one is so dangerous. · Unsplash

Why 'just patch it' isn't good enough here

Because exploitation predates the patch by three weeks, updating the firmware doesn't undo a compromise that may have already happened through the hole. That's why SonicWall's guidance goes further than a normal advisory — re-image, rotate every credential, reset TOTP. This is also the second network-edge zero-day we've covered in a matter of weeks with the identical profile: perimeter security hardware, unauthenticated root-level bugs, real-world exploitation before disclosure — see Cisco's FMC static-credential zero-day and Arista's VeloCloud Orchestrator flaw. Ransomware crews are increasingly treating perimeter appliances as the soft underbelly of otherwise well-defended networks, and this makes three in a row.

  1. Confirm firmware is 12.4.3-03453 / 12.5.0-02835 or later
  2. If it wasn't already, treat the appliance as potentially compromised, not just outdated
  3. Re-image the appliance rather than upgrading in place
  4. Rotate every admin and user password tied to the SMA, and reset TOTP/MFA tokens
  5. Review VPN and access logs back to June 22, 2026 for anomalous sessions

Quick answers

Do I need both CVEs patched, or just one?
Both — they're used together in the observed attacks. Patching only one still leaves part of the chain usable.
Is INC ransomware confirmed as the group behind this?
Rapid7 telemetry links a threat actor using this exact exploit chain to the INC ransomware-as-a-service operation, though SonicWall itself hasn't published formal attribution.
What if I patched after July 14 but was unpatched before that?
SonicWall's guidance is to treat any appliance that was vulnerable and internet-facing as potentially compromised — patching closes the hole but doesn't undo anything that already happened through it.
Are other SonicWall product lines affected?
The advisory covers the SMA 1000 Series specifically; check SonicWall's own advisory for your exact model and firmware before assuming you're clear.

This is becoming the standard playbook for 2026: find or buy a zero-day in whatever sits at the network edge, burn it quietly for weeks against a handful of targets, and let the eventual vendor disclosure become free reconnaissance for everyone else watching. If your organization runs a lot of internet-facing SonicWall gear, this is worth an out-of-band audit today, not a wait-for-the-next-patch-cycle shrug.

Hardware Editor

Ravi Malhotra

Ravi has been building and taking apart PCs since the single-core days — his idea of a good weekend is a repaste and a spreadsheet full of thermals. He covers GPUs, CPUs and the build decisions that actually move frame rates, and he'd rather hand you a benchmark than a press release.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading