Ransomware gangs are using a SonicWall remote-access flaw that was patched a month ago
The American cyber agency CISA has updated its warning about two flaws in SonicWall’s SMA1000 remote access appliances to record that ransomware crews are now using them, BleepingComputer reports. Attackers have been seen installing custom malware on the appliances themselves, in families researchers have named KNUCKLEBALL, Sou5, ROOTRUN and ORANGETAIL.
The pair are catalogued as CVE-2026-15409 and CVE-2026-15410. Security firm Tenable rates the first at the maximum 10 out of 10: it lets someone with no account and no password make the appliance send requests wherever they choose. The second needs an administrator login first, then allows commands to be run on the underlying system.
None of this is new. The flaws were disclosed on 14 July, patches landed in mid-July, and exploitation as a zero-day goes back to 22 June. What has happened since matters more: scans by the Shadowserver Foundation still find more than 380 of these appliances exposed on the internet, nearly a month after the fix was published.
Who this affects
Probably not you, and it is worth saying so plainly. SMA1000 is SonicWall’s enterprise remote access gateway – models 6210, 7210 and 8200v. It is a different product from the SMA100 range and from the TZ firewalls that sit in most small offices. If you have a SonicWall box on the wall keeping your office online, that is almost certainly a TZ and this is not about it.
Where it does apply is the larger end: businesses running a dedicated appliance so staff can reach the network from home or from site. If that describes you, treat it as urgent rather than routine. An appliance like this exists precisely to be reachable from the internet, which means there is no firewall in front of it to hide behind, and a working attack gets somebody a foothold on your network rather than on one laptop.
What to do
- Work out whether you have one, and which one. The model number is on the unit and in the management console. SMA1000 6210, 7210 or 8200v puts you in scope; TZ or SMA100 does not.
- Check the firmware version, not the purchase date. On the 12.4 branch you want 12.4.3-03453 or later; on 12.5, 12.5.0-02835 or later. Anything below those is unpatched however recently the box was bought.
- Assume it may already have been reached. Exploitation started in late June, so an appliance patched in August was exposed for weeks. Patching does not undo an intrusion – have the appliance and the accounts behind it checked properly.
- Ask who is actually responsible for patching it. Network kit gets missed more often than servers do. Somebody should own the firmware on every internet-facing device you have, by name.
- Write down what you expose to the internet. Appliances, remote access, cameras, that one server. If the list does not exist, this is the week to write one.
Where this usually goes wrong
A patch published in July only helps the businesses that installed it. Nearly a month on, hundreds have not – and almost never because somebody decided to skip it. It is because nobody was quite sure whose job it was. That is the bit worth fixing, and it will be the same bit next time.
Knowing what you have facing the internet and keeping it current is exactly what vulnerability scanning is for, and it is one of the five controls behind Cyber Essentials, which asks you to fix flaws like these within fourteen days. We run more than 150 automated checks every hour across the kit we look after, so a missed firmware update turns into a job on a list rather than a surprise six months later.
Call us on 01202 237 273 or book a call.