CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
Read original article ↗AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 appliances, tracked as CVE-2026-15409 and CVE-2026-15410. These flaws, including a critical server-side request forgery (SSRF) vulnerability, were exploited in zero-day attacks as early as June 22, prior to public disclosure. A threat actor known as UTA0533 has been linked to the exploitation of these vulnerabilities to deploy custom malware such as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable systems. CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch within three days.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.