CVE-2026-15409 and CVE-2026-15410 let INC ransomware walk into SMA 1000 appliances as root — SonicWall didn't even know the holes existed until the attacks were already underway.
SonicWall published a security advisory on July 14, 2026 for two flaws in its SMA 1000 Series appliances — the boxes a lot of mid-size companies use for secure remote access. Routine enough, except for one detail: a threat actor had already been using both bugs since June 22, three weeks before SonicWall knew they existed. CVE-2026-15409 and CVE-2026-15410, chained together, let an attacker with no valid credentials tunnel into a company's internal network and run commands as root. If you run an SMA 1000 and haven't patched to 12.4.3-03453 or 12.5.0-02835 yet, this is the one to stop and do today.
How CVE-2026-15409 and CVE-2026-15410 work together
The two bugs aren't dangerous in isolation so much as in sequence. CVE-2026-15409 is a server-side request forgery flaw that lets an attacker open a tunnel from the open internet into services that were only ever meant to be reachable internally. Once inside, CVE-2026-15410 — a code-injection flaw — lets that same attacker run arbitrary operating-system commands. Chain the two together and you get unauthenticated remote code execution as root, on an appliance whose entire job is being the secure gateway into the network.
The two CVEs
CVE-2026-15409
CVSS
10.0
Type
Server-side request forgery
What it lets an attacker do
Open a tunnel from the open internet into internal-only services
CVE-2026-15410
CVSS
7.2
Type
Code injection
What it lets an attacker do
Run arbitrary OS commands once inside
CVSS
Type
What it lets an attacker do
CVE-2026-15409
10.0
Server-side request forgery
Open a tunnel from the open internet into internal-only services
CVE-2026-15410
7.2
Code injection
Run arbitrary OS commands once inside
How this played out
June 22, 2026
Volexity later determines a threat cluster it tracks begins exploiting both flaws as zero-days — weeks before any patch or public advisory existed.
July 14, 2026
SonicWall publishes its advisory for CVE-2026-15409 and CVE-2026-15410, more than three weeks after exploitation began.
Days later
A threat actor connected to the INC ransomware-as-a-service operation starts using the same exploit chain against newly disclosed targets, per Rapid7 telemetry.
Through August 2026
SonicWall's guidance goes beyond patching: re-image affected appliances, rotate every admin and user password, and reset TOTP tokens — the kind of response reserved for boxes that may already be compromised.
SMA 1000 appliances sit at the edge of a company's network by design — exactly why root access on one is so dangerous. · Unsplash
Why 'just patch it' isn't good enough here
Because exploitation predates the patch by three weeks, updating the firmware doesn't undo a compromise that may have already happened through the hole. That's why SonicWall's guidance goes further than a normal advisory — re-image, rotate every credential, reset TOTP. This is also the second network-edge zero-day we've covered in a matter of weeks with the identical profile: perimeter security hardware, unauthenticated root-level bugs, real-world exploitation before disclosure — see Cisco's FMC static-credential zero-day and Arista's VeloCloud Orchestrator flaw. Ransomware crews are increasingly treating perimeter appliances as the soft underbelly of otherwise well-defended networks, and this makes three in a row.
Confirm firmware is 12.4.3-03453 / 12.5.0-02835 or later
If it wasn't already, treat the appliance as potentially compromised, not just outdated
Re-image the appliance rather than upgrading in place
Rotate every admin and user password tied to the SMA, and reset TOTP/MFA tokens
Review VPN and access logs back to June 22, 2026 for anomalous sessions
Quick answers
Do I need both CVEs patched, or just one?
Both — they're used together in the observed attacks. Patching only one still leaves part of the chain usable.
Is INC ransomware confirmed as the group behind this?
Rapid7 telemetry links a threat actor using this exact exploit chain to the INC ransomware-as-a-service operation, though SonicWall itself hasn't published formal attribution.
What if I patched after July 14 but was unpatched before that?
SonicWall's guidance is to treat any appliance that was vulnerable and internet-facing as potentially compromised — patching closes the hole but doesn't undo anything that already happened through it.
Are other SonicWall product lines affected?
The advisory covers the SMA 1000 Series specifically; check SonicWall's own advisory for your exact model and firmware before assuming you're clear.
This is becoming the standard playbook for 2026: find or buy a zero-day in whatever sits at the network edge, burn it quietly for weeks against a handful of targets, and let the eventual vendor disclosure become free reconnaissance for everyone else watching. If your organization runs a lot of internet-facing SonicWall gear, this is worth an out-of-band audit today, not a wait-for-the-next-patch-cycle shrug.