Ransomware Operators Exploit 2 SonicWall SMA1000 Zero-Days for Root Access as CISA Flags KEV Risk
Updated
Updated · linkedin · Aug 11
Ransomware Operators Exploit 2 SonicWall SMA1000 Zero-Days for Root Access as CISA Flags KEV Risk
3 articles · Updated · linkedin · Aug 11
Summary
CISA said CVE-2026-15409 and CVE-2026-15410 are being used in ransomware campaigns against SonicWall SMA1000 appliances, where attackers can gain root control, steal credentials and pivot into internal networks.
A CVSS 10.0 SSRF bug and a 7.2 command-injection flaw form an unauthenticated remote-code-execution chain, letting intruders tunnel to local services, execute code as the CouchDB user and escalate to root.
June 22 forensic evidence shows the zero-day campaign began weeks before SonicWall disclosed and patched the flaws on July 14, leaving a roughly three-week exposure window before fixes were available.
Rapid7 linked the most aggressive post-disclosure activity to INC ransomware, while Volexity found custom implants including KNUCKLEBALL, ROOTRUN and ORANGETAIL, plus signs of LDAP credential capture and domain-controller access from compromised gateways.
SonicWall fixed affected 12.4.3 and 12.5.0 builds in versions 12.4.3-03453 and 12.5.0-02835, but both SonicWall and responders say patching alone is insufficient if appliances were internet-exposed before updating.