Two freshly patched vulnerabilities in SonicWall's SMA 1000 Series appliances are being actively exploited as zero-days by a threat actor linked to the Inc ransomware group, according to incident response telemetry from Rapid7. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, can be chained together to grant an unauthenticated remote attacker full root-level control over the affected device.
SonicWall disclosed the pair this week and pushed out a hotfix, but the disclosure comes after attackers have already weaponized the bugs in the wild.
How the Attack Chain Works
The entry point is CVE-2026-15409, a server-side request forgery (SSRF) flaw in the SMA's "Work Place" web portal. It carries a maximum CVSS score of 10.0 because it requires no authentication whatsoever. An attacker on the open internet can craft requests that trick the portal into reaching out to internal services on their behalf, effectively punching a hole through the network perimeter.
Once inside, the attacker pivots to CVE-2026-15410, a code injection vulnerability in the Appliance Management Console (AMC). Rated 7.2 on the CVSS scale, it demands that the attacker already have access to the administrative UI. Chained with the SSRF bug, it completes the escalation from anonymous outsider to root-level insider.
Rapid7 researchers published a proof-of-concept demonstrating the chain. In observed incidents, the intrusion playbook has been textbook: initial access via the SMA appliance, OS-level command execution, credential and session database theft, and lateral movement toward domain controllers.
Ransomware Deployment Confirmed
The endgame is not merely network access. It is monetization.
"We have successfully prevented exfiltration and encryption in the majority of cases; however, we now have an active case in which ransomware deployment was achieved," said Brett Deroche, director of incident response at Rapid7.
The attackers are not stopping at the edge device. They are harvesting the seeds used to generate one-time login codes, stealing active session databases, and using the compromised SMA as a springboard into the broader corporate network. Double-extortion ransomware, where data is both stolen and encrypted, remains the dominant monetization model for groups operating under the Inc Ransomware-as-a-Service umbrella.
Why SonicWall SMA Appliances Are Prime Targets
SonicWall positions its SMA 1000 Series as a premium secure remote access solution for government agencies, MSSPs, and mid-to-large enterprises. That positioning makes each appliance a high-value target. Compromising the gateway between the public internet and an internal network gives attackers privileged positioning: they can access sensitive systems, create accounts, and drop additional tooling with minimal friction.
This is not SonicWall's first brush with aggressive exploitation. The company's disclosure practices have drawn scrutiny before. Earlier this year, Texas-based SaaS firm Marquis Software Solutions sued SonicWall, alleging the vendor failed to promptly inform customers of an active cyberattack campaign that ultimately enabled a ransomware incident against Marquis.
The Patch Is Not Enough
SonicWall has urged customers to apply the new hotfix immediately. Security researchers agree, but with a critical caveat.
"Patching after a public notice leaves a massive window of vulnerability where attackers are already acting on zero-days," noted John Gallagher, vice president at Viakoo. "Organizations must treat edge devices with an assume-breach mentality, and roll out security updates at scale within minutes to hours, not weeks to months."
Deroche went further. He has seen cases where organizations patched the appliance but skipped a full forensic review, only to find the threat actor had maintained persistence and rolled the patch back to a vulnerable state to preserve access.
"A comprehensive forensic review of the firewall is required to ensure complete eviction," he stressed.
What Organizations Should Do Now
For any organization running an SMA 1000 Series appliance, the priority is twofold: apply the hotfix, then hunt. Check for signs of prior compromise, review logs for anomalous AMC access, and validate that no unauthorized accounts or backdoors remain. The patch closes the door, but only a forensic sweep confirms no one is still inside.
The broader lesson is about speed. Zero-days in edge security appliances do not stay theoretical for long. When the vendor notice hits, the race between defenders and already-embedded attackers is already underway.