CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being exploited in ransomware attacks and have been added to its KEV catalog.

CISA has also marked both vulnerabilities as known to be used in ransomware campaigns, making immediate remediation essential for organizations using exposed SMA1000 systems.

SonicWall disclosed the vulnerabilities on July 14, 2026, under advisory SNWLID-2026-0008. The company said its Product Security Incident Response Team investigated multiple cases of active exploitation and urged customers to install the available platform hotfixes as soon as possible.

The affected products include SMA 6210, SMA 7210, and SMA 8200v appliances running vulnerable platform-hotfix releases 12.4.3 or 12.5.0. SonicWall firewall SSL-VPN services and the SMA 100 Series product line are not affected.

SonicWall SMA1000 Vulnerabilities Exploited

CVE-2026-15409 is the most serious issue. It is a server-side request forgery vulnerability in the SMA1000 Workplace interface, with a CVSS severity score of 10.0. A remote attacker does not need valid credentials or user interaction to exploit it.

The flaw can cause the appliance to make requests to unintended internal or external locations. In practical terms, this can turn an internet-facing remote-access device into a path toward services that should not be reachable from the public internet.

The second flaw, CVE-2026-15410, is an improper code-generation issue, also described as code injection, in the SMA1000 Appliance Management Console.

It carries a CVSS score of 7.2 and can allow an authenticated administrator to execute arbitrary operating-system commands under certain conditions.

Security researchers have reported that attackers can chain the two vulnerabilities: the first weakness enables access to protected internal functionality. At the same time, the second can be abused to escalate access and gain root-level control of the appliance.

This combination is especially dangerous because SMA1000 devices often sit at the edge of corporate networks and handle remote user access.

A successful compromise may allow attackers to steal credentials, access session information, establish persistence, move into internal systems, and prepare to deploy ransomware.

Reporting indicates that the INC Ransomware operation has emerged as a major actor abusing the vulnerability chain. At the same time, earlier exploitation activity was linked to a cluster tracked as UTA0533.

SonicWall has released fixed versions 12.4.3-03453 and later, plus 12.5.0-02835 and later. There is no workaround, so patching is the primary defense.

CISA required U.S. federal agencies to patch the flaws by July 17, 2026, and urged organizations to check for signs of compromise before closing incidents.

SonicWall advised defenders to review extraweb_access.log for unexpected requests involving /api/login, /api/logout, or /wsproxy, especially suspicious host parameters and HTTP 101 responses.

Teams should also inspect ctrl-service.log for suspicious hotfix rollback activity and check whether /var/lib/unit/conf.json contains routes for the non-legitimate API paths.

If indicators of compromise are found, SonicWall recommends re-imaging physical appliances or redeploying virtual appliances, changing all user and administrator passwords, and resetting TOTP tokens.

Security teams should treat an internet-exposed, unpatched SMA1000 appliance as a high-priority incident-response case, not simply a routine patching task.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware appeared first on Cyber Security News.