CISA flags SonicWall SMA1000 flaws as actively exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware gangs are actively exploiting two vulnerabilities in SonicWall's SMA1000 enterprise VPN gateway, according to BleepingComputer. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, were patched by SonicWall in mid-July after the company warned they were being exploited in zero-day attacks.
Incident response firm Volexity previously reported that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 to deploy custom malware including KNUCKLEBALL and ROOTRUN on vulnerable VPN appliances. CISA added both flaws to its Known Exploited Vulnerabilities catalog on July 14, ordering U.S. federal agencies to patch within three days. Security watchdog Shadowserver tracks over 380 SMA1000 appliances exposed online, though some may have already been secured.