Updated
Updated · linkedin · Aug 11
Ransomware Operators Exploit 2 SonicWall SMA1000 Zero-Days for Root Access as CISA Flags KEV Risk
Updated
Updated · linkedin · Aug 11

Ransomware Operators Exploit 2 SonicWall SMA1000 Zero-Days for Root Access as CISA Flags KEV Risk

3 articles · Updated · linkedin · Aug 11

Summary

  • CISA said CVE-2026-15409 and CVE-2026-15410 are being used in ransomware campaigns against SonicWall SMA1000 appliances, where attackers can gain root control, steal credentials and pivot into internal networks.
  • A CVSS 10.0 SSRF bug and a 7.2 command-injection flaw form an unauthenticated remote-code-execution chain, letting intruders tunnel to local services, execute code as the CouchDB user and escalate to root.
  • June 22 forensic evidence shows the zero-day campaign began weeks before SonicWall disclosed and patched the flaws on July 14, leaving a roughly three-week exposure window before fixes were available.
  • Rapid7 linked the most aggressive post-disclosure activity to INC ransomware, while Volexity found custom implants including KNUCKLEBALL, ROOTRUN and ORANGETAIL, plus signs of LDAP credential capture and domain-controller access from compromised gateways.
  • SonicWall fixed affected 12.4.3 and 12.5.0 builds in versions 12.4.3-03453 and 12.5.0-02835, but both SonicWall and responders say patching alone is insufficient if appliances were internet-exposed before updating.

Insights

How did a trusted SonicWall VPN gateway become the ultimate Trojan horse for the INC ransomware cartel?
What hidden persistence mechanisms might survive on your network even after rebuilding a compromised SonicWall SMA1000 appliance?
Why are ransomware affiliates increasingly targeting perimeter security devices instead of traditional phishing methods to breach networks?