Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: sonicwall (5 articles)Clear

INC ransomware becomes the main group exploiting SonicWall VPN appliances

Resecurity reports that the INC ransomware operation has become the dominant group exploiting two SonicWall SMA1000 VPN appliance flaws, accelerating its attacks since early August. The pair, CVE-2026-15409 and CVE-2026-15410, were exploited as zero-days before SonicWall patched them in mid-July, and can be chained to gain root on the appliance and extract credentials, session databases, and one-time-password data. Many appliances remain unpatched or already compromised, leaving footholds attackers can reuse. Victims listed recently span private and government organizations across several countries, and some reported follow-up emails and phone calls from people claiming to help with the ransomware.

Check
Confirm SonicWall SMA1000 appliances have the mid-July fixes, and because pre-patch exploitation was common, run a compromise assessment and rotate credentials, sessions, and one-time-password secrets the appliance handled.
Affected
Organizations running SonicWall SMA1000 appliances (CVE-2026-15409, CVE-2026-15410); INC ransomware is actively chaining the flaws to root devices, and unpatched or already-compromised appliances remain reusable footholds.
Fix
Patch, then re-image compromised appliances and reset all credentials and one-time-password tokens they processed, restrict management access, and treat unsolicited offers of ransomware help as part of the extortion.

SonicWall VPN appliances were backdoored for weeks before the flaws were disclosed

Incident response firm Volexity detailed how attackers chained two SonicWall SMA1000 flaws as zero-days weeks before the vendor disclosed them, reaching root and installing malware built specifically for the appliances. A previously unknown actor it tracks as UTA0533 began exploiting on June 22, nearly three weeks before the July 14 advisory. The chain starts with CVE-2026-15409 against the /wsproxy endpoint, letting an unauthenticated attacker open WebSocket tunnels to services meant to be reachable only from the appliance itself, then uses CVE-2026-15410 for command execution. With root, the actor could read stored credentials, capture traffic, and intercept credentials the appliance processes.

Check
Patch SMA1000 appliances to the fixed releases, then check them against Volexity's published indicators, since patching alone does not remove an implant left during the pre-disclosure exploitation window.
Affected
Organizations running SonicWall SMA1000 6210, 7210, or 8200v appliances (CVE-2026-15409, CVE-2026-15410); attackers held root before patches existed, with malware purpose-built for these devices and access to processed credentials.
Fix
Where indicators are found, SonicWall advises re-imaging hardware or redeploying virtual appliances, changing all user and administrator passwords, and resetting one-time-password tokens, since credentials the appliance handled should be treated as exposed.

SonicWall SMA1000 remote-access appliances hit by exploited zero-day flaws

SonicWall is warning that two flaws in its SMA1000 remote-access appliances are being actively exploited as zero-days, and has released hotfixes. CVE-2026-15409 is an unauthenticated server-side request forgery bug in the appliance's WorkPlace interface that lets an attacker make the device send requests to internal systems, turning an edge gateway into a pivot point. CVE-2026-15410 is a code-injection flaw in the management console that lets an administrator run operating-system commands, and SonicWall rates the overall advisory a top CVSS score of 10.0. Both were added to CISA's exploited-vulnerabilities catalog, with a federal deadline of July 17. Because exploitation is confirmed, any unpatched appliance should be treated as potentially compromised.

Check
Identify all SonicWall SMA1000 appliances, including standby and disaster-recovery nodes, apply the hotfix immediately, and review authentication logs, new accounts, outbound connections, and configuration changes for signs of intrusion.
Affected
Organizations running SonicWall SMA1000 remote-access appliances (CVE-2026-15409, CVE-2026-15410); attackers are actively exploiting the flaws, and the request-forgery and code-injection bugs could be chained to reach and run commands on internal systems.
Fix
Apply SonicWall's hotfix now, restrict management interfaces to trusted networks until patched, and because exploitation is confirmed, run a compromise assessment and assume unpatched appliances may already be backdoored.

SonicWall Gen6 SSL-VPN MFA bypass (CVE-2024-12802) actively exploited - firmware patch alone insufficient, LDAP reconfiguration required

ReliaQuest has documented active in-the-wild exploitation of CVE-2024-12802, a SonicWall Gen6 SSL-VPN MFA bypass that hits Gen6 devices even after they apply the firmware patch. SonicWall's advisory makes clear that on Gen6 hardware, the firmware update alone does not fix it - administrators must also delete the LDAP configuration that uses userPrincipalName, remove cached LDAP users, drop the SSL VPN User Domain back to LocalDomain, reboot, and rebuild the LDAP config without userPrincipalName. Gen7 and Gen8 devices are patched by firmware alone. Intrusions observed between February and March 2026 looked like ransomware initial-access broker activity with 30-60 minute Cobalt Strike and BYOVD attempts.

Check
Inventory SonicWall Gen6 SSL-VPN appliances and confirm the LDAP reconfiguration was done after the firmware patch. Search VPN logs for 30-60 minute logins from new IPs in the last 90 days.
Affected
SonicWall Gen6 SSL-VPN devices running patched firmware but with LDAP still configured to use userPrincipalName in the 'Qualified login name' field. Gen7 and Gen8 are patched by firmware alone.
Fix
On Gen6: delete the existing LDAP config, remove cached LDAP users, drop the SSL VPN User Domain back to LocalDomain, reboot, then rebuild LDAP without userPrincipalName per SonicWall's advisory.

SonicWall patches three SonicOS firewall flaws after CrowdStrike disclosed them - the worst lets attackers reach the management interface without logging in (CVE-2026-0204)

SonicWall released emergency firmware updates for Gen 6, Gen 7, and Gen 8 firewalls after CrowdStrike's research team disclosed three SonicOS flaws on April 29. The worst is CVE-2026-0204 (CVSS 8.0), a weak authentication bug in the management interface that lets an attacker on an adjacent network reach management functions without logging in - and from there change firewall rules, disable security protections, or open new holes. The other two are post-authentication: CVE-2026-0205 is a path traversal that breaks out of restricted directories, and CVE-2026-0206 is a buffer overflow that crashes the firewall. No public exploits yet.

Check
Patch every SonicWall Gen 6, Gen 7, and Gen 8 firewall to the latest firmware today, and confirm no SonicWall management interface or SSL-VPN is reachable from the public internet.
Affected
Gen 6 firewalls (TZ 300/400/500/600, NSA, SM, SOHO) running 6.5.5.1-6n or older. Gen 7 firewalls and NSv (TZ270-TZ670, NSa 2700-6700, NSsp, NSv on ESX/KVM/Hyper-V/AWS/Azure) running 7.0.1-5169 or 7.3.1-7013 or older. Gen 8 (TZ80-TZ680, NSa 2800-5800) running 8.1.0-8017 or older.
Fix
Upgrade to Gen 8 firmware 8.2.0-8009, Gen 7 firmware 7.3.2-7010, or Gen 6 6.5.5.2-28n. Until patched, disable HTTP and HTTPS firewall management on all interfaces, disable SSL-VPN, and restrict management to SSH only from trusted IPs. Take a full configuration backup before upgrading Gen 6 - downgrading from 6.5.5.2-28n deletes all LDAP users and resets MFA.