a ransomware crew had root on SonicWall's boxes for weeks before anyone noticed

CVE-2026-15409 and CVE-2026-15410 let INC ransomware walk into SMA 1000 appliances as root — SonicWall didn't even know the holes existed until the…

Aliteq
Ravi Malhotra · Hardware Editor

The short version

CVE-2026-15409 (CVSS 10.0, SSRF) and CVE-2026-15410 (CVSS 7.2, code injection) affect SonicWall SMA 1000 Series appliances.

The short version

Chained together, they let an unauthenticated attacker tunnel into internal networks and run commands as root.

The short version

Volexity found evidence the bugs were exploited as zero-days from June 22, 2026 — three weeks before SonicWall's July 14 advisory.

The short version

A threat actor connected to the INC ransomware-as-a-service operation began using the same chain within days of public disclosure.

The short version

Fixed firmware: 12.4.3-03453 and 12.5.0-02835 or later. SonicWall recommends re-imaging affected appliances, not just patching.

If you're an MSP or IT admin

Don't treat this as 'patch when convenient.' Assume compromise if your SMA 1000 has been internet-facing and unpatched at any point since June 22, 2026, and follow SonicWall's full remediation — not…

Aliteq

Read the full story

a ransomware crew had root on SonicWall's boxes for weeks before anyone noticed

Read the full story on Aliteq