Skip to content
SonicWall SMA1000 Crisis: Zero-Day Exploitation Uncovered

SonicWall SMA1000 Crisis: Zero-Day Exploitation Uncovered

First seen 13 Sep 2026, 15:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 15:57 UTC
  • CVE-2026-15409 and CVE-2026-15410 are critical vulnerabilities with CVSS scores of 10.0.
  • Attackers exploited these vulnerabilities to gain root access and harvest MFA tokens.
  • Remediation requires a complete rebuild of affected SonicWall appliances.

The SonicWall SMA1000 crisis initiated on June 22, 2026, due to two critical vulnerabilities: CVE-2026-15409 and CVE-2026-15410. CVE-2026-15409, a CVSS 10.0 SSRF flaw, allowed attackers to open WebSocket tunnels to localhost services without authentication. This was followed by CVE-2026-15410, which enabled escalation from a low-privilege account to root access. Attackers exploited these vulnerabilities to harvest TOTP MFA seeds, allowing them to generate valid MFA tokens indefinitely. The threat actor UTA0533 utilized a sophisticated toolkit, including ROOTRUN and ORANGETAIL, and the INC Ransomware group was identified as the primary actor. Victims were reported across multiple countries, including the US and Australia. Remediation requires a full rebuild of compromised appliances, as firmware updates do not eliminate backdoors. The incident highlights significant risks associated with the management plane of VPN appliances.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-06-22
SonicWall SMA1000 crisis begins
Two critical vulnerabilities CVE-2026-15409 and CVE-2026-15410 were identified, leading to major security concerns.
Tech.Yahoo
2026-07-14
CVE-2026-15409 and CVE-2026-15410 published
Both vulnerabilities were published and added to the CISA KEV list for active exploitation.
Forkast.News
2026-07-17
Initial exploitation observed
Exploitation of the vulnerabilities began, affecting organizations in multiple countries.
Tech.Yahoo
2026-08-01
Victims identified
Victims of the exploitation were confirmed in the US, Australia, UAE, Colombia, and Switzerland.
Forkast.News
2026-09-13
Remediation guidance issued
Organizations were advised to fully rebuild compromised SonicWall appliances due to persistent threats.
Tech.Yahoo

More articles in this cluster (2)

Following this threat?

Track INC Ransomware, Knuckleball and Sonicwall in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed