Ransomware actors exploit SonicWall SMA1000 flaws to execute commands and deploy malware
Ransomware gangs are actively exploiting two critical flaws in SonicWall SMA1000 appliances to deploy custom malware. These vulnerabilities allow for server-side request forgery and arbitrary command execution. Update your SMA1000 firmware immediately to mitigate these active threats.
Summary
Threat actors have begun exploiting two recently patched security flaws in SonicWall SMA1000 appliances. The SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) for VPN access to internal networks.
CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, noting that they are being used in ransomware campaigns. While SonicWall released patches in mid-July, researchers have tracked exploitation occurring as early as June 22, weeks before the public disclosure of these flaws.
Technical details
The two vulnerabilities target different stages of an attack on the SMA1000 appliance:
- CVE-2026-15409: A server-side request forgery (SSRF) vulnerability. This flaw could allow a remote, unauthenticated attacker to cause the appliance to make requests to unintended locations.
- CVE-2026-15410: A code injection vulnerability. Under specific conditions, this allows a remote authenticated attacker with administrator privileges to execute arbitrary operating system commands.
The threat actor tracked as UTA0533 has been observed using these vulnerabilities to deploy several pieces of custom malware on vulnerable VPN appliances, including KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL.
Exploitation status
These flaws were exploited in zero-day attacks prior to the release of official patches. CISA's inclusion of these CVEs in the KEV catalog on July 14 came with a directive for Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
Shadowserver currently tracks over 380 SMA1000 appliances exposed online, though some of these assets may have already applied the necessary updates.
Why this matters for defenders
The SMA1000 serves as a gateway into corporate networks. Successful exploitation allows attackers to move from the appliance into the internal environment. This follows a pattern of recent vulnerabilities in SonicWall products; in December, a separate flaw (CVE-2025-40602) was used in zero-day attacks to gain root privileges via the Appliance Management Console (AMC).
The current exploitation by ransomware gangs increases the risk of full network compromise and data encryption following initial entry through the VPN gateway.
Defender guidance
Prioritize these actions to secure your remote access infrastructure:
- Apply Hotfixes: Immediately upgrade SMA1000 appliances to the latest hotfix release provided by SonicWall.
- Verify Exposure: Evaluate all internet-facing SMA1000 assets and ensure they are running patched firmware versions.
- Monitor for Malware: Scan environments for indicators of custom malware such as
KNUCKLEBALL,Sou5,ROOTRUN, orORANGETAIL. - Audit Administrator Activity: Monitor for unusual command execution or unauthorized administrative actions on the appliance, particularly following potential code injection attempts.
