Two actively exploited vulnerabilities in SonicWall SMA1000 appliances have been confirmed by the vendor, with Rapid7 observing likely ransomware-motivated attacks beginning 22 June.
Summary
- SonicWall has confirmed two zero-days — CVE-2026-15409 (critical) and CVE-2026-15410 (CVSS 7.2) — affecting SMA1000 appliances, both exploited before patches were available.
- When chained, the vulnerabilities allow an unauthenticated attacker to achieve complete system compromise via remote code execution.
- Rapid7 observed exploitation beginning 22 June and assesses the likely objective is ransomware, though exfiltration and encryption were prevented in observed cases.
- CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue.
- SonicWall states fewer than 5,000 SMA1000 units are in its monitored fleet, but warns patching alone is insufficient — breach should be assumed where exposure existed.
What Has Happened
SonicWall disclosed two zero-day vulnerabilities on Tuesday affecting its SMA1000 appliances. The first, CVE-2026-15409, carries a maximum severity rating and permits attackers to make authenticated requests without valid credentials. The second, CVE-2026-15410, is rated 7.2 and enables authenticated command injection. SonicWall credited an internal employee with discovering the defects but has not disclosed when that discovery occurred or the earliest known date of exploitation.
The Chain That Matters
Individually, each vulnerability is serious. Together, they are considerably more so. Landon Rice, senior exploit developer at VulnCheck, described the combined effect plainly: when the two are chained, an attacker can move from zero access to complete system compromise on the affected appliance. Ben Harris, founder and CEO at watchTowr, noted that both characteristics — prior exploitation and a clear path to remote code execution from the internet — compound the risk for any organisation running exposed SMA1000 devices.
Exploitation Timeline and Attribution
Researchers at Rapid7 told CyberScoop they first observed exploitation of both vulnerabilities on 22 June. Overlapping tactics, techniques and procedures across observed incidents led Rapid7 to conclude a single threat group or attacker is likely responsible. Seth Lazarus, senior manager of detection and response services at Rapid7, stated that in the cases his team observed, the goal appeared to be ransomware, although the actors were prevented from completing exfiltration or encryption. SonicWall has not attributed the attacks to a known group, nor described the attacker’s origins or motivations.
Vendor Response
SonicWall released a patch concurrent with its public disclosure and shared indicators of compromise to assist customers in hunting for malicious activity. Bret Fitzgerald, senior director of global communications at SonicWall, said speed of response was a priority, noting the company developed a remediation script within days of becoming aware of the issue and that mitigation efforts are already under way. Support staff are actively assisting customers dealing with suspicious activity. The vendor has confirmed it investigated multiple cases of active exploitation and that both vulnerabilities have been chained in real attacks.
Scope and Broader Context
SonicWall monitors approximately one million sensors globally, and SMA1000 appliances represent fewer than 5,000 units within that footprint. The precise number of affected customers has not been disclosed by SonicWall or third-party researchers. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalogue on Tuesday. This latest incident sits within a sustained pattern: 17 SonicWall product defects have been added to the CISA catalogue since late 2021, ten of which are linked to ransomware campaigns. A separate 2025 incident saw an undisclosed state-sponsored actor compromise SonicWall’s cloud environment and steal firewall configurations belonging to all SonicWall customers.
Why it matters
SonicWall appliances occupy a privileged position on the network perimeter, making them a high-value target. The chaining of these two vulnerabilities means an external attacker with no prior access can achieve full control of an SMA1000 device — a foothold that has historically translated into ransomware deployment across the broader environment. The pattern of sustained exploitation across SonicWall products, combined with the confirmed ransomware motivation in current cases, means security leaders should treat any SMA1000 exposure as an incident-response trigger, not merely a patching task. The vendor’s own warning that patching alone is insufficient reinforces the need for active threat hunting and assumption of breach where these appliances were internet-exposed before remediation.
What to do now
- Upgrade all SMA1000 appliances to the latest software version released by SonicWall upon disclosure of CVE-2026-15409 and CVE-2026-15410.
- Review the indicators of compromise published by SonicWall and conduct threat hunting across SMA1000 appliances and connected network segments.
- Contact SonicWall support to request the remediation script the vendor has developed and to engage assistance if suspicious activity is detected.
- Treat any SMA1000 appliance that was internet-exposed before patching as potentially compromised and initiate breach-response procedures accordingly.
- Verify whether both CVEs appear in your organisation’s vulnerability management backlog and confirm they are flagged as CISA Known Exploited Vulnerabilities requiring prioritised remediation.
