CVE-2026-15409
Summary
CVE-2026-15409 (CVSS 10.0) is a critical vulnerability in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, discovered by Volexity during incident response investigations. The flaw was exploited as a zero-day by threat actors, including the INC Ransomware operation, which chained it with CVE-2026-15410 to achieve root-level device compromise.
Details
CVE-2026-15409 (CVSS 10.0) can be chained with CVE-2026-15410 (CVSS 7.2) to facilitate arbitrary command execution and full device takeover without authentication. The INC Ransomware group emerged as the dominant actor exploiting these flaws, claiming 885 victims to date with activity accelerating since the beginning of August 2026. Rapid7 noted attackers leveraged the foothold to extract high-value credentials and active session data.
Remediation
Patches were released by SonicWall in mid-July 2026. Organisations using SMA 1000 series appliances should apply patches immediately.
Related
- Sonicwall Sma Zero Day โ Combined coverage of both CVEs
- Cve 2026 15410 โ Chained vulnerability (CVSS 7.2)
- Inc Ransomware Emerges As Dominant Actor Exploiting Sonicwall Sma 1000 Flaws โ INC Ransomware campaign
Sources
- The Hacker News
- Volexity analysis by Sean Koessel and Steven Adair