CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA says ransomware gangs are now exploiting two recently patched SonicWall SMA1000 flaws, including a maximum-severity SSRF vulnerability tracked as CVE-2026-15409. The issues were previously used in zero-day attacks by UTA0533 to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL against exposed SMA1000 appliances. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #KNUCKLEBALL #Sou5 #ROOTRUN #ORANGETAIL

Keypoints

  • CISA confirmed active exploitation of two SonicWall SMA1000 vulnerabilities.
  • One of the flaws is a critical server-side request forgery issue.
  • SonicWall had already warned that the bugs were being used in zero-day attacks.
  • UTA0533 used the flaws to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL.
  • CISA added the vulnerabilities to the KEV Catalog and ordered rapid patching.

Read More: https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/