Tech.Yahoo SonicWall SMA1000 Crisis: Zero-Day Exploitation Uncovered
Article Content
- •CVE-2026-15409 and CVE-2026-15410 are critical vulnerabilities with CVSS scores of 10.0.
- •Attackers exploited these vulnerabilities to gain root access and harvest MFA tokens.
- •Remediation requires a complete rebuild of affected SonicWall appliances.
The SonicWall SMA1000 crisis initiated on June 22, 2026, due to two critical vulnerabilities: CVE-2026-15409 and CVE-2026-15410. CVE-2026-15409, a CVSS 10.0 SSRF flaw, allowed attackers to open WebSocket tunnels to localhost services without authentication. This was followed by CVE-2026-15410, which enabled escalation from a low-privilege account to root access. Attackers exploited these vulnerabilities to harvest TOTP MFA seeds, allowing them to generate valid MFA tokens indefinitely. The threat actor UTA0533 utilized a sophisticated toolkit, including ROOTRUN and ORANGETAIL, and the INC Ransomware group was identified as the primary actor. Victims were reported across multiple countries, including the US and Australia. Remediation requires a full rebuild of compromised appliances, as firmware updates do not eliminate backdoors. The incident highlights significant risks associated with the management plane of VPN appliances.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track INC Ransomware, Knuckleball and Sonicwall in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…