Inc Ransomware Exploits SonicWall SMA Zero-Days
ID: fcedeeb8-a430-56ce-a932-7a2fdd266c96
STIX ID: report--fcedeeb8-a430-56ce-a932-7a2fdd266c96
Feed Name: Dark Reading
Two zero-day vulnerabilities in SonicWall SMA 1000 Series (CVE-2026-15409 SSRF with CVSS 10.0 and CVE-2026-15410 code injection CVSS 7.2) are being actively exploited in the wild by actors linked to the Inc ransomware group to gain unauthenticated RCE, steal credentials, move laterally to high-value targets (including domain controllers), and deploy ransomware; CISA added the flaws to its KEV catalog and SonicWall released a hotfix while responders warn that patching alone may not evict persistent attackers and full forensic reviews are required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
