Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.
SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks.
“SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory,” the company warned at the time. “Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.”
Incident response firm Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed online, although some may already have been secured against attacks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog on July 14, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency said.
While SonicWall has yet to update its original advisory to confirm that CVE-2026-15409 and CVE-2026-15410 are targeted in ransomware attacks, CISA has now also flagged them as exploited by ransomware gangs in recent updates to the KEV Catalog.
In December, the company warned customers to patch another vulnerability (CVE-2025-40602) in the SonicWall SMA1000 Appliance Management Console (AMC) that was being chained by hackers in zero-day attacks to gain root privileges.
One month earlier, SonicWall linked state-sponsored hackers to a September security breach that exposed customers’ firewall configuration backup files after researchers warned of over 100 SonicWall SSLVPN accounts compromised using stolen credentials.
In September, it also pushed a firmware update to help remove OVERSTEP rootkit malware deployed in attacks targeting SMA 100 series devices.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
You must be logged in to post a comment Login