CISA says ransomware gangs are now exploiting two recently patched SonicWall SMA1000 flaws, including a maximum-severity SSRF vulnerability tracked as CVE-2026-15409. The issues were previously used in zero-day attacks by UTA0533 to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL against exposed SMA1000 appliances. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #KNUCKLEBALL #Sou5 #ROOTRUN #ORANGETAIL
Keypoints
- CISA confirmed active exploitation of two SonicWall SMA1000 vulnerabilities.
- One of the flaws is a critical server-side request forgery issue.
- SonicWall had already warned that the bugs were being used in zero-day attacks.
- UTA0533 used the flaws to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL.
- CISA added the vulnerabilities to the KEV Catalog and ordered rapid patching.