news.mlab.sh
Back to the feed
threat-intel

Inc Ransomware Exploits SonicWall SMA Zero-Days

High
Summary

A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal credentials, and deploy ransomware. The vulnerabilities, discovered by Rapid7, enable attackers to bypass input validation and execute OS-level commands, and SonicWall has released a hotfix, but experts stress that simply patching isn't enough – organizations need to proactively hunt for intrusions and quickly remediate compromised devices.

Two newly reported vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances have allowed a major ransomware group, Inc, to gain remote code execution and escalate privileges, facilitating widespread network infiltration. On July 14, SonicWall published a security advisory regarding CVE-2026-15409 and CVE-2026-15410, which enable attackers to bypass input validation and execute OS-level commands.

Rapid7’s telemetry indicates that threat actors have been leveraging these vulnerabilities as zero-days, performing a textbook intrusion flow: using the appliances as an initial access vector, exploiting the vulnerabilities to bypass input validation and execute commands at the OS level. They then established persistent access by stealing credentials, active session databases, and the seeds used to generate one-time login codes, and subsequently performed lateral movement from compromised SMAs across corporate networks, most notably targeting domain controllers.

CVE-2026-15409, a server-side request forgery (SSRF) issue in the SMA’s “Work Place” Web interface, requires no authentication and has a CVSS score of 10/10. CVE-2026-15410, requiring an already accessible device, earned a CVSS score of 7.2. SonicWall has released a hotfix to address these vulnerabilities, and strongly encourages customers to implement it.

However, experts warn that simply applying the vendor patch is insufficient, especially if the appliance was already compromised. Rapid7’s director of incident response, Brett Deroche, notes that “We observed the threat actor maintaining persistence and rolling the newly applied patch back to a vulnerable state to maintain access.” He emphasizes the need for a comprehensive forensic review of the firewall to ensure complete eviction.

SonicWall’s SMA appliances are particularly valuable targets due to their use in government agencies, managed security service providers (MSSPs), and medium to multinational enterprises. The company’s approach to vulnerability disclosure and remediation has also been subject to scrutiny, with a Texas-based SaaS company, Marquis Software Solutions, suing SonicWall for failing to promptly inform it of a cyberattack campaign that enabled a ransomware attack against Marquis.

Organizations need to shift from a reactive patching strategy to a proactive approach, treating edge and network-adjacent appliances with an ‘assume-breach’ mentality and rolling out security updates within minutes to hours, not weeks to months. Ultimately, the goal is to identify and quickly remove persistent attackers, even if a patch has been applied.

Read the full article at Dark Reading