When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.

July 17, 2026

Two newly reported vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances have been exploited as zero-days by a major ransomware group.

On July 14, the cybersecurity vendor SonicWall published a security advisory regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410. Together they could allow any random, unauthenticated attacker to gain remote code execution (RCE) powers and then run commands on the box at the root level.

Indeed, this is already happening. According to telemetry from Rapid7, a threat actor connected to the infamous Inc ransomware-as-a-service (RaaS) group has been using CVE-2026-15409 and CVE-2026-15410 as zero-days, burrowing into multiple enterprise networks, sweeping up credentials, and setting the stage for ransomware deployment.