Internet-facing SonicWall SMA 1000 appliances are under active exploitation through a zero-click, pre-authentication chain that combines CVE-2026-15409 and CVE-2026-15410 to deliver unauthenticated root compromise. Resecurity reported exploitation began by at least June 22, before SonicWall released July fixes, and identified INC Ransomware as the primary actor observed using the full chain. The attack abuses a wsproxy bypass to reach localhost-only services and then uses a path traversal flaw in the hotfix-removal process to execute a staged script with root privileges.
Affected products include SMA 6210, SMA 7210, SMA 8200v, and vCMS in the SMA 1000 line, while SonicWall firewall SSL VPN and SMA 100 Series products are not affected. Post-compromise activity included persistent backdoors, an HTTP forwarding proxy, a memory-resident web shell, packet capture targeting unencrypted LDAP traffic, startup and routing changes for persistence, credential-theft opportunities, and use of the appliance as a pivot into internal networks. SonicWall advised organizations to upgrade to fixed firmware, preserve logs, hunt for indicators of compromise, and treat exposed devices as potentially breached, with rebuilds or factory resets and credential rotation recommended where intrusion is suspected.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Resecurity observed INC Ransomware using direct phone calls and emails as added pressure during extortion negotiations following exploitation of SonicWall SMA 1000 devices. The report identified contact infrastructure including the domain helprans[.]com and said victims were contacted by a caller identifying himself as "Andrew."
Resecurity reported that INC Ransomware accelerated activity in early August 2026, publishing multiple new victims on its data leak site after exploiting SonicWall SMA 1000 appliances. The newly listed victims included private and government organizations in the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.
SC Media, citing Resecurity, reported that attackers exploiting SonicWall SMA 1000 appliances stole session databases and TOTP seeds from compromised devices. The disclosure meant password resets alone were insufficient and affected users needed full MFA re-enrollment.
The references state that patches for the SonicWall SMA 1000 exploit chain arrived in July 2026, after exploitation had already been observed. Fixed firmware versions include 12.4.3-03453 or later and 12.5.0-02835 or later.
Resecurity reported that attackers were exploiting a zero-click chain against internet-facing SonicWall SMA 1000 appliances by at least June 22, 2026. The chain combined CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated root compromise.
Huntress researchers reported a recent spree in which attackers compromised 30 SonicWall customers in less than two days, highlighting the scale and speed of ongoing exploitation of SMA devices. The report underscored sustained ransomware targeting of SonicWall appliances.
Resecurity identified INC Ransomware as the primary threat actor observed exploiting the full SonicWall SMA 1000 vulnerability chain. The reporting also documented post-compromise activity including persistent backdoors, a forwarding proxy, a memory-resident web shell, and packet capture of unencrypted LDAP traffic.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceacn.gov.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.