Two zero-day flaws in SonicWall's Secure Mobile Access (SMA) 1000-series VPN appliances have moved from stealthy espionage to full-blown ransomware, with the INC Ransomware gang emerging as the dominant actor exploiting them. Security researchers at Rapid7, Resecurity, and Volexity confirmed the escalation in reporting published August 3, 2026, and the group listed its most recent victim on August 2 — placing this squarely inside the current attack window.

What happened

The two vulnerabilities are tracked as CVE-2026-15409, a maximum-severity server-side request forgery (SSRF) flaw reportedly rated CVSS 10, and CVE-2026-15410, a high-severity command injection issue (reported CVSS 7.2). Chained together, they let an unauthenticated remote attacker reach restricted internal services and execute arbitrary commands on the appliance, then escalate to root.

According to Volexity, exploitation began as a zero-day as early as June 22, 2026 — attributed to a threat cluster tracked as UTA0533 — and ran undetected for roughly four weeks. SonicWall shipped patches (versions 12.4.3-03453 and 12.5.0-02835) in mid-July, and CISA added the flaws to its Known Exploited Vulnerabilities catalog the same month. Affected hardware includes the SMA1000 6210, 7210, and 8200v models.

The attackers deployed custom tooling: KNUCKLEBALL (a Python dropper), the Suo5 HTTP reverse proxy, the ORANGETAIL Java web shell, and ROOTRUN, a privilege-escalation utility. Once inside, they harvested high-value credentials, active session databases, and — most damaging — TOTP (time-based one-time password) MFA seed configurations.

Why it matters

Stealing MFA seeds is the detail that makes this campaign dangerous even after patching. With the seed values, attackers can generate valid one-time codes themselves, meaning a rushed patch does not evict them. Rapid7's Douglas McKee confirmed INC Ransomware weaponized the access for encryption and extortion; the group now claims roughly 885 victims across Australia, the U.S., the UAE, Colombia, Switzerland, and beyond. Victims have reported follow-up pressure by email and phone from people posing as recovery "helpers."

How to protect yourself

Edge VPN and remote-access appliances remain among the most attacked assets on the internet precisely because they sit at the network boundary. This incident is a reminder that with these devices, patching is the start of remediation — not the end.