On July 14, 2026, SonicWall disclosed two vulnerabilities in its SMA 1000 Series secure remote access appliances, the SSL VPN gateways many mid-size and large organizations use as the front door into their internal networks. The first, CVE-2026-15409, is a maximum-severity (CVSS 10.0) pre-authentication flaw in the appliance’s wsproxy component that lets an unauthenticated attacker open a WebSocket tunnel to services that are supposed to be reachable only from localhost. The second, CVE-2026-15410 (CVSS 7.2), is a path-traversal bug in the appliance’s hotfix-removal workflow that allows an attacker who has reached that internal service to escalate to root. Chained together, the two flaws turn a single unauthenticated request into full administrative control of the appliance. Most alarmingly, researchers determined that the pair had already been exploited as a zero-day since at least June 22, 2026, roughly three weeks before a patch existed, by a cluster tracked as UTA0533.
In the weeks since, INC Ransomware has emerged as the dominant actor weaponizing the exploit chain, and its activity has accelerated sharply since the start of August. Researchers report that intruders are using their root level foothold to harvest saved credentials, active session databases, and TOTP multi-factor authentication seeds directly from compromised appliances, giving them durable, MFA bypassing access even after a device is patched. SonicWall has warned that patching alone does not remediate a prior compromise. Organizations that operated an internet facing SMA 1000 appliance at any point since mid June are advised to hunt for indicators of compromise and, where evidence of intrusion is found, reimage or redeploy the appliance entirely, rotate all passwords associated with the device, re-enrol all MFA authenticators, and invalidate any active VPN sessions or authentication tokens.