CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
Brief
The U. S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410 , are being exploited in ransomware attacks and have been added to its KEV catalog.
CISA has also marked both vulnerabilities as known to be used in ransomware campaigns, making immediate remediation essential for organizations using exposed SMA1000 systems.
SonicWall disclosed the vulnerabilities on July 14, 2026, under advisory SNWLID-2026-0008 . The company said its Product Security Incident Response Team investigated multiple cases of active exploitation and urged customers to install the available platform hotfixes as soon as possible.
The affected products include SMA 6210, SMA 7210, and SMA 8200v appliances running vulnerable platform-hotfix releases 12.
- 3 or 12.
- 0.
