CVE-2026-15409
Known exploited · CISA KEV
CISA federal remediation date Jul 17 · date passed
Vulnerabilities · 55 days ago
The risk has shifted from simple intrusion to direct extortion: a successful SonicWall SMA1000 chain can now give an attacker full control of the appliance, enough to steal data and deploy ransomware from the same foothold. Patch-and-move-on thinking misses that the gateway itself can become the monetization point, not just the entry door.
CyberScoop reports that INC ransomware is now the most commonly named actor using CVE-2026-15409 and CVE-2026-15410 together, after the flaws were already being exploited before SonicWall disclosed and patched them on July 14. Rapid7 said early activity starting June 22 came from common hosted infrastructure and was mostly unsuccessful, but post-disclosure INC activity used different infrastructure and moved from access to ransomware deployment in short order; at least one case included ransomware, and the same chain has been used for both theft and encryption.
That leaves government and national-sector teams with a dual-blast-radius problem on a remote-access appliance: exposed data can be leaked even if the box is repaired, and availability can be hit in the same run.
Known exploited · CISA KEV
CISA federal remediation date Jul 17 · date passed
Known exploited · CISA KEV
CISA federal remediation date Jul 17 · date passed
3 sources covering this story
Prolific ransomware group behind SonicWall zero-day attacks
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion.
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
INC Ransomware is suspected of chaining CVE-2026-15409 and CVE-2026-15410 to steal credentials, TOTP seeds, and reach internal networks.
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.
Part of the PlainSec briefing for 2026-08-05