Resecurity | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain

Resecurity | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain
SonicWall’s SMA 1000 series was hit by two actively exploited zero-days, CVE-2026-15409 and CVE-2026-15410, which let attackers chain a pre-auth /wsproxy bypass and a path-traversal flaw to gain root access on exposed VPN appliances. The abuse was attributed to UTA0533 and later linked to INC Ransomware, with observed malware including ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #INCRansomware #ROOTRUN #KNUCKLEBALL #Suo5 #ORANGETAIL

Keypoints

  • CVE-2026-15409 allows unauthenticated access to the /wsproxy endpoint.
  • CVE-2026-15410 enables path traversal in remove_hotfix to execute files as root.
  • The two flaws together can turn a single HTTP request into full VPN appliance compromise.
  • Attackers used the chain to deploy ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL.
  • Organizations should patch immediately and hunt for signs of compromise on SMA 1000 appliances.

Read More: https://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain