Two critical, unauthenticated zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances are under active exploitation by at least two threat actor groups: the Inc Ransomware gang and a newly identified group tracked as UTA0533. The vulnerabilities, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), can be chained to achieve unauthenticated remote code execution (RCE) with root-level privileges on affected VPN devices. Exploitation began in late June 2026, weeks before patches were available. CISA has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for organizations to patch immediately and hunt for signs of compromise.
The attack leverages a combination of a Server-Side Request Forgery (SSRF) and a command injection flaw. The primary actors identified are Inc Ransomware, a known Ransomware-as-a-Service (RaaS) operation using the flaws for initial access, and UTA0533, which has deployed sophisticated, custom malware tailored for the SonicWall SMA environment. Volexity reports that UTA0533 began its campaign as early as June 22, 2026. The attackers' goals appear to be establishing persistent access, credential theft, and creating a foothold for further lateral movement or ransomware deployment within victim networks.
The attack chain begins with the exploitation of CVE-2026-15409, a critical SSRF vulnerability in the SMA's "Work Place" web interface. This allows an unauthenticated attacker to force the appliance to make web requests to internal network resources, effectively bypassing perimeter security. The attacker then uses this SSRF to access the Appliance Management Console (AMC).
Once access to the AMC is gained, the attacker exploits CVE-2026-15410, a command injection vulnerability. By chaining these two flaws, the threat actor can execute arbitrary commands on the underlying operating system with root privileges.
UTA0533 demonstrated advanced capabilities by deploying a custom malware suite:
T1190 - Exploit Public-Facing Application) to gain root access.Suo5: An open-source HTTP proxy tool for tunneling traffic.T1505.003 - Web Shell).setuid binary named ROOTRUN to maintain elevated privileges (T1548.003 - SUID and SGID). They also modify startup scripts to ensure the malware persists across reboots (T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder).T1003.008 - OS Credential Dumping: /etc/passwd and /etc/shadow).Inc Ransomware operators were observed by Rapid7 using the same exploit chain primarily as an initial access vector to breach enterprise networks, steal credentials, and set the stage for their ransomware deployment.
The exploitation of these vulnerabilities poses a critical risk to organizations. A compromised VPN appliance provides a direct entry point into the corporate network, bypassing perimeter defenses. The potential impact includes:
Given that exploitation began before patches were available, organizations with vulnerable appliances are at high risk of having been compromised.
No specific file hashes, IP addresses, or domains were provided in the source articles.
Security teams may want to hunt for the following patterns which could indicate related activity:
*/workplace/java/tmp/Organizations should assume compromise if they were running a vulnerable version of the SMA 1000 series firmware prior to July 14, 2026.
/workplace/ path and any access to the AMC from non-standard sources. This aligns with D3FEND's D3-NTA: Network Traffic Analysis.D3-FA: File Analysis on the appliance's filesystem.CRITICAL: SonicWall has stated that simply applying the patch will NOT remove an existing compromise. A full device reset is required if compromise is confirmed or suspected.
Immediate action is required to mitigate this threat.
D3-SU: Software Update.D3-NI: Network Isolation.New technical details reveal SSRF exploited CouchDB with default credentials for RCE, deploying memory-resident malware.
Further analysis reveals attackers leveraged the SSRF (CVE-2026-15409) to access a local CouchDB service configured with default 'admin:admin' credentials. This access was then used to inject and execute arbitrary commands (CVE-2026-15410) with root privileges. The deployed KNUCKLEBALL malware is noted to be memory-resident, injecting malicious components directly into legitimate SonicWall processes to evade file-based detection and maintain stealthy, long-term persistence for credential theft and network monitoring.
INC Ransomware confirmed as primary actor in widespread SonicWall SMA zero-day attacks, now impacting global sectors with new pressure tactics.
New intelligence confirms UTA0533 is linked to the INC Ransomware operation, which is now conducting widespread attacks across the United States, Australia, UAE, Colombia, and Switzerland, affecting both government and private sectors. Attackers are employing new pressure tactics, including phone calls and emails, to coerce victims into ransom negotiations. Additional hunting hints include monitoring for requests to /cgi-bin/sslvpn-client, unexpected python processes, and anomalous SonicWall SMA logs. New mitigation advice emphasizes network segmentation and assuming compromise for unpatched systems.
Exploitation by threat actor UTA0533 reportedly begins.
SonicWall releases patches for CVE-2026-15409 and CVE-2026-15410.
CISA adds both CVEs to its Known Exploited Vulnerabilities (KEV) catalog.
Deadline for U.S. federal agencies to apply the SonicWall patches as mandated by CISA.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.