logo

Inc Ransomware Exploits SonicWall SMA Zero-Days

ID: fcedeeb8-a430-56ce-a932-7a2fdd266c96

STIX ID: report--fcedeeb8-a430-56ce-a932-7a2fdd266c96

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

Author: Nate Nelson

...
...

Two zero-day vulnerabilities in SonicWall SMA 1000 Series (CVE-2026-15409 SSRF with CVSS 10.0 and CVE-2026-15410 code injection CVSS 7.2) are being actively exploited in the wild by actors linked to the Inc ransomware group to gain unauthenticated RCE, steal credentials, move laterally to high-value targets (including domain controllers), and deploy ransomware; CISA added the flaws to its KEV catalog and SonicWall released a hotfix while responders warn that patching alone may not evict persistent attackers and full forensic reviews are required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.